DocumentCode :
1694485
Title :
A collaborative architecture for intrusion detection systems with intelligent agents and knowledge-based alert evaluation
Author :
Yu, Jinqiao ; Reddy, Y. V Ramana ; Selliah, Sentil ; Kankanahalli, Srinivas ; Reddy, Sumitra ; Bharadwaj, Vijayanand
Author_Institution :
Lane Dept. of Comput. Sci. & Electr. Eng., West Virginia Univ., Morgantown, WV, USA
Volume :
2
fYear :
2004
Firstpage :
271
Abstract :
Current reactive and standalone network security products are not capable of withstanding the thriving of diversified network threats. As a result, a security paradigm where integrated security devices or systems collaborate closely to achieve enhanced protection and provide multilayer defenses is emerging. We present a collaborative architecture design for multiple intrusion detection systems to work together to detect real-time network intrusions. The architecture is composed of three parts: collaborative alert aggregation, knowledge-based alert evaluation and alert correlation. The architecture is aimed at reducing the alert overload by correlating from multiple sensors to generate condensed views, reducing false positives by integrating network and host system information and correlating events based on logical relations to generate global and synthesized alert report. The first two parts of the architecture have been implemented and the implementation results are presented in this paper.
Keywords :
groupware; security of data; software agents; alert correlation; alert overload reduction; collaborative alert aggregation; collaborative architecture; integrated security devices; integrated security systems; intelligent agents; intrusion detection systems; knowledge-based alert evaluation; multilayer defenses; network security products; real-time network intrusion detection; Application software; Collaboration; Collaborative work; Computer architecture; Computer networks; Data security; IP networks; Information security; Intelligent agent; Intrusion detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Supported Cooperative Work in Design, 2004. Proceedings. The 8th International Conference on
Print_ISBN :
0-7803-7941-1
Type :
conf
DOI :
10.1109/CACWD.2004.1349196
Filename :
1349196
Link To Document :
بازگشت