Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

Multi-Pattern GPU Accelerated Collision-Less Rabin-Karp for NIDS

  • Abstract
  • Highlights & Summary
  • PDF
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

In the domain of network communication, network intrusion detection systems (NIDS) play a crucial role in maintaining security by identifying potential threats. NIDS relies on packet inspection, often using rule-based databases to scan for malicious patterns. However, the expanding scale of internet connections hampers the rate of packet inspection. To address this, some systems employ GPU accelerated pattern matching algorithms. Yet, this approach is susceptible to denial of service (DOS) attacks, inducing hashing collisions and slowing inspection. This research introduces a GPU-optimized variation of the Rabin-Karp algorithm, achieving scalability on GPUs while resisting DOS attacks. Our open-source solution (https://github.com/AnasAbbas1/NIDS) combines six polynomial hashing functions, eliminating the need for false-positive validation. This leads to a substantial improvement in inspection speed and accuracy. The proposed system ensures minimal packet misclassification rates, solidifying its role as a robust tool for real-time network security.

Similar Papers
  • Research Article
  • Cite Count Icon 2
  • 10.1201/1086/43320.11.2.20020501/36768.7
ISPs and Denial of Service Attacks
  • May 1, 2002
  • Information Systems Security
  • K Narayanaswamy

A denial of service (DOS) attack is any malicious attempt to deprive legitimate customers of their ability to access services, such as a Web server. DOS attacks fall into two broad categories: • Server vulnerability DOS attacks — attacks that exploit known bugs in operating systems and servers. These attacks typically will use the bugs to crash programs that users routinely rely upon, thereby depriving those users of their normal access to the services provided by those programs. Examples of vulnerable systems include all operating systems, such as Windows NT or Linux, and various Internet-based services such as DNS, Microsoft's IIS Servers, Web servers, etc. All of these programs, which have important and useful purposes, also have bugs that hackers exploit to bring them down or hack into them. This kind of DOS attack usually comes from a single location and searches for a known vulnerability in one of the programs it is targeting. Once it finds such a program, the DOS attack will attempt to crash the program to deny service to other users. Such an attack does not require high bandwidth. • Packet flooding DOS attacks — attacks that exploit weaknesses in the Internet infrastructure and its protocols. Floods of seemingly normal packets are used to overwhelm the processing resources of programs, thereby denying users the ability to use those services. Unlike the previous category of DOS attacks, which exploit bugs, flood attacks require high bandwidth in order to succeed. Rather than use the attacker's own infrastructure to mount the attack (which might be easier to detect), the attacker is increasingly likely to carry out attacks through intermediary computers (called zombies) that the attacker has earlier broken into. Zombies are coordinated by the hacker at a later time to launch a distributed DOS (DDOS) attack on a victim. Such attacks are extremely difficult to trace and defend with the present-day Internet. Most zombies come from home computers, universities, and other vulnerable infrastructures. Often, the owners of the computers are not even aware that their machines are being co- opted in such attacks. The hacker community has invented numerous scripts to make it convenient for those interested in mounting such attacks to set up and orchestrate the zombies. Many references are available on this topic.1–4

  • Conference Article
  • Cite Count Icon 6
  • 10.1109/icict.2017.8320164
Detection and mitigation of Denial of Service (DoS) attacks using performance aware Software Defined Networking (SDN)
  • Dec 1, 2017
  • Wajahat Navid + 1 more

Software Defined Networking (SDN) stands to transmute our modern networks and data centers, opening them up into highly agile frameworks that can be reconfigured depending on the requirement. Denial of Service (DoS) attacks are considered as one of the most destructive attacks. This paper, is about DoS attack detection and mitigation using SDN. DoS attack can minimize the bandwidth utilization, leaving the network unavailable for legitimate traffic. To provide a solution to the problem, concept of performance aware Software Defined Networking is used which involves real time network monitoring using sFlow as a visibility protocol. So, OpenFlow along with sFlow is used as an application to fight DoS attacks. Our analysis and results demonstrate that using this technique, DoS attacks are successfully defended implying that SDN has promising potential to detect and mitigate DoS attacks.

  • Conference Article
  • Cite Count Icon 11
  • 10.1109/ies50839.2020.9231699
Implementation of SDN-based IDS to protect Virtualization Server against HTTP DoS attacks
  • Sep 1, 2020
  • Saifudin Usman + 2 more

Virtualization and Software-defined Networking (SDN) are emerging technologies that play a major role in cloud computing. Cloud computing provides efficient utilization, high performance, and resource availability on demand. However, virtualization environments are vulnerable to various types of intrusion attacks that involve installing malicious software and denial of services (DoS) attacks. Utilizing SDN technology, makes the idea of SDN-based security applications attractive in the fight against DoS attacks. Network intrusion detection system (IDS) which is used to perform network traffic analysis as a detection system implemented on SDN networks to protect virtualization servers from HTTP DoS attacks. The experimental results show that SDN-based IDS is able to detect and mitigate HTTP DoS attacks effectively.

  • Conference Article
  • Cite Count Icon 18
  • 10.1109/fuzz-ieee.2017.8015461
D-FRI-WinFirewall: Dynamic fuzzy rule interpolation for Windows Firewall
  • Jul 1, 2017
  • Nitin Naik + 4 more

Dynamic fuzzy rule interpolation (D-FRI) consists of functionalities of fuzzy rule interpolation and dynamically refinement of the fuzzy rule base. It can be integrated with any fuzzy intelligent system to extend the system's capabilities in addition to its normal fuzzy reasoning. Systems security is one of the areas that require dynamic monitoring due to the nature of possible threats; static rule-based systems cannot cover all reoriented security threats accurately in the long run. D-FRI provides a possible solution to such problems, potentially making various security tools (e.g., those for firewall, intrusion detection and traffic analysis) more effective. As a particular application, this paper exploits D-FRI to dynamically support Microsoft Windows Firewall, resulting in a robust system named D-FRI-WinFirewall. Given the general utility of Windows Firewall, the impact of this work is far-reaching. The work reported here focusses on the monitoring and prevention of denial of service (DoS) attacks, which is not possible by utilising the standard Windows Firewall alone. In particular, two sub-systems are designed, implemented and tested within D-FRI-WinFirewall, with an effort to detect and prevent two serious types of DoS attack: ICMP DoS attack and UDP DoS attack, leading the Windows Firewall to outperform popular and expensive firewalls, which are yet unable to handle DoS attacks.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 6
  • 10.3844/ajassp.2012.909.916
A Discrete Event Simulator for Extensive Defense Mechanism for Denial of Service Attacks Analysis
  • Jun 1, 2012
  • American Journal of Applied Sciences
  • Tanha

Problem statement: Seeking for defense mechanisms against low rate De nial of Service (DoS) attacks as a new generation of DoS attacks ha s received special attention during recent years. A s a decisive factor, evaluating the performance of th e offered mitigation techniques based on different metrics for determining the viability and ability o f these countermeasures requires more research. Approach: The development of a new generalized discrete event simulator has been deliberated in detail. The research conducted places high emphasis on the benefits of creating a customized discrete event simulator for the analysis of security and in particular the DoS attacks. The simulator possesse s a niche in terms of the small scale, low execution ti me, portability and ease of use. The attributes and mechanism of the developed simulator is complemented with the proposed framework. Results: The simulator has been extensively evaluated and has pr oven to provide an ideal tool for the analysis and exploration of DoS attacks. In-depth analysis is en abled by this simulator for creating multitudes of defense mechanisms against HTTP low rate DoS attacks. The acquired results from the simulation tool have been compared against a simulator from the same domain. Subsequently, it enables the validation of developed simulator utilizing selected performan ce metrics including mean in-system time, average delay and average buffer size. Conclusion: The proposed simulator serves as an efficient and scalable performance analysis tool for the analysis of HTTP low rate DoS attack defense mechanism. Future work can encompass the development of discrete event simulators for analysis of other security issues such as Intrusion Detection Systems.

  • Research Article
  • 10.62225/2583049x.2026.6.1.5766
Investigating Denial of Service (DOS) Attacks in a High Traffic System
  • Feb 7, 2026
  • International Journal of Advanced Multidisciplinary Research and Studies
  • Arthur Bupambo + 1 more

The increasing reliance on networked systems for communication, commerce, and critical infrastructure has significantly amplified the risk of Denial of Service (DoS) attacks, one of the most prevalent and damaging forms of cyberattacks. These attacks aim to overwhelm a system’s resources, rendering services unavailable to legitimate users, which can have severe consequences for organizations and critical infrastructure. This study focuses on the design, development, and implementation of a machine learning-based classification model capable of detecting and mitigating various types of DoS attacks, including Ping of Death, TCP SYN Flood, and Distributed Denial of Service (DDoS) attacks. To achieve this, simulated network traffic is analyzed to extract critical features such as packet size, protocol type, packet count, source IP, and other behavioral patterns that serve as key indicators of malicious activity. The extracted features are used to train a Random Forest Classifier, a robust machine learning model known for its accuracy and reliability in classification tasks. The proposed system operates in real-time, dynamically analyzing incoming traffic, identifying anomalous patterns associated with DoS attacks, and automatically mitigating them by blocking malicious source IP addresses. This approach not only enhances detection accuracy but also minimizes response time, offering a proactive defense mechanism against evolving cyber threats. A comprehensive evaluation of the system is conducted using key performance metrics, including accuracy, precision, recall, and F1-score, which collectively demonstrate the effectiveness of the model in distinguishing legitimate traffic from malicious traffic. The results reveal that the system achieves a high detection accuracy of 95%, with strong precision and recall values, confirming its capability to identify DoS attacks while minimizing false positives and negatives. The findings of this research contribute to the advancement of machine learning applications in the field of cybersecurity, particularly in the domain of intrusion detection and prevention systems. The integration of machine learning algorithms such as the Random Forest Classifier enables the system to adapt to diverse attack scenarios and high-traffic environments, making it scalable for practical deployment in real-world systems. Furthermore, the system’s ability to operate in real time ensures that critical services remain available to legitimate users, mitigating the economic and operational damage caused by DoS attacks. However, the study also highlights challenges related to resource consumption and scalability, particularly in large-scale networks with significant traffic volumes. These limitations underscore the need for further research to optimize resource usage, improve the scalability of the detection model, and explore additional machine learning techniques to enhance performance further. In conclusion, this study demonstrates the feasibility and effectiveness of a machine learning-based approach to detecting and mitigating DoS attacks, providing a scalable, real-time solution that addresses the growing cybersecurity threats faced by modern networked systems. By offering a high level of accuracy and dynamic response capabilities, the system represents a significant step toward strengthening the resilience of critical infrastructure and organizational networks against cyberattacks. Future research will focus on refining the model for large-scale networks, integrating it with existing cybersecurity frameworks, and exploring hybrid detection methods to address emerging attack patterns and techniques. the study emphasizes the importance of leveraging feature engineering techniques to enhance the performance of the classification model by incorporating temporal and spatial analysis of network traffic. By analyzing traffic flow rates, session durations, and inter-packet intervals, the system can better differentiate between legitimate high-traffic activities and malicious attack patterns. Furthermore, the integration of threat intelligence feeds and real-time network monitoring tools enhances the system’s adaptability to emerging attack vectors and zero-day threats. The model's architecture allows for modular updates, enabling seamless incorporation of new features and machine learning algorithms as attack strategies evolve. To further improve system resilience, the study explores combining traditional signature-based detection with anomaly-based methods to create a hybrid intrusion detection system (HIDS) capable of detecting both known and unknown attack types. This hybrid approach ensures a comprehensive defense mechanism while reducing the likelihood of false positives and negatives. In addition, the study proposes incorporating cloud-based deployment models to enable distributed detection across geographically dispersed networks, offering scalability and robust protection for enterprises operating in diverse environments. Finally, the inclusion of real-time visualizations and alert mechanisms provides administrators with actionable insights into network performance, enabling rapid response and effective resource allocation during attack scenarios.

  • Book Chapter
  • Cite Count Icon 2
  • 10.1002/047148296x.tie037
Denial of Service Attacks
  • Jan 3, 2004
  • The Internet Encyclopedia
  • E Eugene Schultz

This chapter focuses on the very serious problem of denial of service (DoS) attacks against computer systems and networks. DoS attacks are attacks designed to disrupt, overwhelm, and/or damage computing resources and data. These attacks are aimed not against confidentiality of data or integrity of systems and data, but rather against availability of systems and data. Attackers launch DoS attacks for a wide variety of reasons. The probability of success is high, due in large part to the fact that the Internet itself has not been designed for security. The cost of DoS attacks is often high—several well‐known attacks have reportedly cost organizations billions of dollars. Many types of DoS attacks have surfaced so far, including resource starvation attacks, buffer overflow attacks, and packet fragmentation attacks. Distributed denial of service (DDoS) attacks, attacks in which programs planted in multiple systems cooperate, represent an even higher level of threat. Preventing DoS attacks is difficult in the first place due to a plethora of reasons; limiting the potential for damage and disruption is often the most cost‐effective strategy. Hot sites, cold sites, use of uninterruptible power supplies (UPSs) and Redundant Array of Independent Drives (RAID) solutions, and other measures can limit the damage from DoS attacks. Using properly configured and maintained firewalls is one of the best single prevention measures. Additionally, using packet filters on systems, keeping up with patches, limiting services that run on these systems, and using other measures go a long way in helping prevent susceptibility to DoS attacks.

  • Conference Article
  • Cite Count Icon 6
  • 10.1109/icsnc.2006.31
Defending against Distributed Denial of Service (DDoS) Attacks with Queue Traffic Differentiation over Micro-MPLS-based Wireless Networks
  • Jan 1, 2006
  • Scott Fowler + 1 more

Traditional security research has been on privacy or authentication. Unfortunately, attacks on wireless media cannot be simply addressed using traditional security methods [1]. An example of a security threat which is difficult to address using traditional network security techniques is Denial of Service (DoS) attacks. Under DoS attacks it is difficult to provide legitimate users their fair shares of bandwidth. However, it is important to allocate a fair share of bandwidth for multimedia traffic requiring Quality of Service. In this paper we address the issue of DoS attacks between mobile nodes and MPLS domains by proposing a queue differentiation policy at the entry point of the MPLS domain. We also investigated DoS attacks of the entry point (Foreign Domain Agent) into Micro-MPLS-based networks (otherwise know a Hierarchical Mobile MPLS (HMPLS)) [2]. Our simulation results show that our proposed technique provides maximum resource utilization by increasing the throughput of multimedia traffic while the network is under DoS attacks.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 3
  • 10.1155/2012/268781
A Methodology to Counter DoS Attacks in Mobile IP Communication
  • Jan 1, 2012
  • Mobile Information Systems
  • Sazia Parvin + 2 more

Similar to wired communication, Mobile IP communication is susceptible to various kinds of attacks. Of these attacks, Denial of Service (DoS) attack is considered as a great threat to mobile IP communication. The number of approaches hitherto proposed to prevent DoS attack in the area of mobile IP communication is much less compared to those for the wired domain and mobile ad hoc networks. In this work, the effects of Denial of Service attack on mobile IP communication are analyzed in detail. We propose to use packet filtering techniques that work in different domains and base stations of mobile IP communication to detect suspicious packets and to improve the performance. If any packet contains a spoofed IP address which is created by DoS attackers, the proposed scheme can detect this and then filter the suspected packet. The proposed system can mitigate the effect of Denial of Service (DoS) attack by applying three methods: (i) by filtering in the domain periphery router (ii) by filtering in the base station and (iii) by queue monitoring at the vulnerable points of base-station node. We evaluate the performance of our proposed scheme using the network simulator NS-2. The results indicate that the proposed scheme is able to minimize the effects of Denial of Service attacks and improve the performance of mobile IP communication.

  • Conference Article
  • Cite Count Icon 23
  • 10.1109/eit.2007.4374444
Design and implementation of an intrusion detection system for wireless sensor networks
  • May 1, 2007
  • Dmitriy Martynov + 3 more

As a relatively recent and emerging technology, wireless sensor networks (WSNs) are beginning to be deployed frequently in a wide variety of environments ranging from military and emergency environments to natural and embedded environments. For example, a security system may be deployed using WSNs as outlined in M. Turon, J. Suh (Apr. 2005), and P. Dutta., et al., (Apr. 2005). Furthermore, WSNs are of particular interest to adversaries due to their frequent deployments in open and unprotected environments. Preventive mechanisms can sometimes be applied to protect WSNs from an assortment of attacks. However, in many cases, a more sophisticated methodology needs to be applied for situations in which intrusions or attacks cannot necessarily be anticipated in advance. In such instances, an intrusion detection system is warranted. For WSNs, one of the primary concerns deals with availability of the network and individual nodes. Denial of service (DoS) attacks are a particularly great threat to WSNs. The effects of a DoS attack are described extensively in A.D. Wood and J.A. Stankovic (Oct. 2002),and http://www.tinyos.net. WSNs are particularly vulnerable to failure under such attacks because of their limited energy, processing capacity, and storage. An effective DoS attack merely has to deplete the resources of the nodes to render them unavailable. In this paper we design and implement a preliminary intrusion detection system (IDS) for WSNs that addresses the security concern of DoS attacks and fits the demands and restrictions of WSNs.

  • Conference Article
  • Cite Count Icon 1
  • 10.1109/ibcast.2016.7429898
Formal specifications of Denial of Service attacks in Wireless Sensor Networks
  • Jan 1, 2016
  • Kashif Saghar + 3 more

Wireless Sensor Networks (WSN) are composed of small, low cost, resource-constrained computing nodes equipped with low power wireless transceivers. Their unattended nature and possible deployment in hostile environmental conditions poses several challenges in ensuring that a WSN is formed effectively and survives long enough to fulfill its function. WSN nodes are vulnerable to many Denial of Services(DoS) attacks. To secure WSN still against attacks many innovative solutions/protocols have been proposed. However, a number of ambiguities exist in the definition of these DoS attacks. To remove these ambiguities and to clarify our specifications we represented the DoS attacks in a formal modeling notation Z. The specifications are written in a bottom-up approach starting from the basic definitions (like node, message etc), specifying simple operations of WSN (like receive, transmit etc), complex operations (like eavesdrop key, node capture etc) and going all the way up to formally define the DoS attacks. Different WSN routing protocols are then specified to confirm their vulnerability against DoS attacks. Use of Formal methods, thus, confirms how vulnerable a particular routing protocol is against a particular attack. This is a novel work and to the best of our knowledge DoS attacks have not yet been formally defined.

  • Conference Article
  • Cite Count Icon 5
  • 10.1109/icumt.2018.8631212
Denial of Service Attack Generator in Apache JMeter
  • Nov 1, 2018
  • Stepan Grabovsky + 5 more

Cyber attacks are currently a major threat to individuals as well as businesses or institutions. Denial of service (DoS) attacks are very common cyber attacks that focuses on availability of network services or network devices. This paper deals with developing of new modules of DoS attacks and network traffic generator into Apache JMeter that is designed to load test functional behavior and measure performance. Modules developed together with Appache JMeter tool can test a network infrastructure and find weak localities prone to DoS cyber attacks. One goal of this paper is to compare tools for stress testing of web servers and services. The network generator module of DoS attacks allows stress testing of networks based on the Transmission Control Protocol/Internet Protocol (TCP/.IP). With using the generator developed it is possible to test the availability of network devices when exposure to DoS attacks. Selected cyber attacks targeting on the availability of network resources (DoS attacks) that can test a resistance of a network infrastructure are described in the article. DoS attacks described have been implemented in the Apache JMeter tool together with the design and the development of the network generator of DoS attacks. New modules can be used to test a resistance of network infrastructure. Finally, the measured values using the generator developed are presented and discussed.

  • Research Article
  • Cite Count Icon 9
  • 10.1080/00207217.2017.1279230
A hybrid protection approaches for denial of service (DoS) attacks in wireless sensor networks
  • Jan 21, 2017
  • International Journal of Electronics
  • Mahalakshmi Gunasekaran + 1 more

ABSTRACTWireless sensor network (WSN) contains the distributed autonomous devices with the sensing capability of physical and environmental conditions. During the clustering operation, the consumption of more energy causes the draining in battery power that leads to minimum network lifetime. Hence, the WSN devices are initially operated on low-power sleep mode to maximise the lifetime. But, the attacks arrival cause the disruption in low-power operating called denial of service (DoS) attacks. The conventional intrusion detection (ID) approaches such as rule-based and anomaly-based methods effectively detect the DoS attacks. But, the energy consumption and false detection rate are more. The absence of attack information and broadcast of its impact to the other cluster head (CH) leads to easy DoS attacks arrival. This article combines the isolation and routing tables to detect the attack in the specific cluster and broadcasts the information to other CH. The intercommunication between the CHs prevents the DoS attacks effectively. In addition, the swarm-based defence approach is proposed to migrate the fault channel to normal operating channel through frequency hop approaches. The comparative analysis between the proposed table-based intrusion detection systems (IDSs) and swarm-based defence approaches with the traditional IDS regarding the parameters of transmission overhead/efficiency, energy consumption, and false positive/negative rates proves the capability of DoS prediction/prevention in WSN.

  • Research Article
  • Cite Count Icon 75
  • 10.1007/s13042-019-00925-6
Automatically synthesizing DoS attack traces using generative adversarial networks
  • Feb 20, 2019
  • International Journal of Machine Learning and Cybernetics
  • Qiao Yan + 4 more

Artificial intelligence (AI) technology ruling people is still the scene in the science fiction film, but hackers using AI technology against existing security measures is an inescapable trend. Network intrusion detection systems (NIDS) based deep learning such as convolutional neural network (CNN) have reached a very high detection rate. But we propose DoS-WGAN, a common architecture that uses the Wasserstein generative adversarial networks (WGAN) with gradient penalty technology to evade network traffic Classifiers. To camouflage offensive denial of service (DoS) attack traffic as normal network traffic, DoS-WGAN automatically synthesizes attack traces that can defeat a existing NIDS/network security defense for DoS cases. Information entropy is used to measure the dispersing performance of generated DoS attack traffic. The generated DoS attack traffic is so similar to the normal traffic that detection algorithm cannot distinguish between them. When we input the generated DoS attack traffic to a NIDS based on CNN in our experiments, the detection rate drops to $$47.6\%$$ from $$97.3\%$$. To make the training more stable, we integrate the Standardized Euclidean distance and the information entropy to evaluate the training process. We believe that AI technology will play a particularly important role in the game of network attack and defense.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 37
  • 10.23851/mjs.v28i2.508
Network Intrusion Detection System (NIDS) in Cloud Environment based on Hidden Naïve Bayes Multiclass Classifier
  • Apr 11, 2018
  • Al-Mustansiriyah Journal of Science
  • Hafza A Mahmood

Cloud Environment is next generation internet based computing system that supplies customiza-ble services to the end user to work or access to the various cloud applications. In order to provide security and decrease the damage of information system, network and computer system it is im-portant to provide intrusion detection system (IDS. Now Cloud environment are under threads from network intrusions, as one of most prevalent and offensive means Denial of Service (DoS) attacks that cause dangerous impact on cloud computing systems. This paper propose Hidden naïve Bayes (HNB) Classifier to handle DoS attacks which is a data mining (DM) model used to relaxes the conditional independence assumption of Naïve Bayes classifier (NB), proposed sys-tem used HNB Classifier supported with discretization and feature selection where select the best feature enhance the performance of the system and reduce consuming time. To evaluate the per-formance of proposal system, KDD 99 CUP and NSL KDD Datasets has been used. The experi-mental results show that the HNB classifier improves the performance of NIDS in terms of accu-racy and detecting DoS attacks, where the accuracy of detect DoS is 100% in three test KDD cup 99 dataset by used only 12 feature that selected by use gain ratio while in NSL KDD Dataset the accuracy of detect DoS attack is 90 % in three Experimental NSL KDD dataset by select 10 fea-ture only.

Save Icon
Up Arrow
Open/Close
Setting-up Chat
Loading Interface