Title :
A collaborative architecture for intrusion detection systems with intelligent agents and knowledge-based alert evaluation
Author :
Yu, Jinqiao ; Reddy, Y. V Ramana ; Selliah, Sentil ; Kankanahalli, Srinivas ; Reddy, Sumitra ; Bharadwaj, Vijayanand
Author_Institution :
Lane Dept. of Comput. Sci. & Electr. Eng., West Virginia Univ., Morgantown, WV, USA
Abstract :
Current reactive and standalone network security products are not capable of withstanding the thriving of diversified network threats. As a result, a security paradigm where integrated security devices or systems collaborate closely to achieve enhanced protection and provide multilayer defenses is emerging. We present a collaborative architecture design for multiple intrusion detection systems to work together to detect real-time network intrusions. The architecture is composed of three parts: collaborative alert aggregation, knowledge-based alert evaluation and alert correlation. The architecture is aimed at reducing the alert overload by correlating from multiple sensors to generate condensed views, reducing false positives by integrating network and host system information and correlating events based on logical relations to generate global and synthesized alert report. The first two parts of the architecture have been implemented and the implementation results are presented in this paper.
Keywords :
groupware; security of data; software agents; alert correlation; alert overload reduction; collaborative alert aggregation; collaborative architecture; integrated security devices; integrated security systems; intelligent agents; intrusion detection systems; knowledge-based alert evaluation; multilayer defenses; network security products; real-time network intrusion detection; Application software; Collaboration; Collaborative work; Computer architecture; Computer networks; Data security; IP networks; Information security; Intelligent agent; Intrusion detection;
Conference_Titel :
Computer Supported Cooperative Work in Design, 2004. Proceedings. The 8th International Conference on
Print_ISBN :
0-7803-7941-1
DOI :
10.1109/CACWD.2004.1349196