DocumentCode :
2080438
Title :
A Novelty-Driven Approach to Intrusion Alert Correlation Based on Distributed Hash Tables
Author :
Hofmann, Alexander ; Dedinski, Ivan ; Sick, Bernhard ; de Meer, Hermann
Author_Institution :
Univ. of Passau, Passau
fYear :
2007
fDate :
1-4 July 2007
Firstpage :
71
Lastpage :
78
Abstract :
Distributed intrusion detection and prevention plays an increasingly important role in securing computer networks. In a distributed intrusion detection system, alerts or high-level meta-alerts are exchanged, aggregated, and correlated in a cooperative fashion to overcome the limitations of conventional intrusion detection systems. Substantial progress has been made, but current systems still suffer from various drawbacks: Most of them only distribute the data collection and not the analysis itself or they rely on a hierarchical or even centralized organization and/or communication architecture. Furthermore, the alerts or meta-alerts are usually aggregated at a pre-defined location and there is no reduction of the vast amount of alerts prior to distribution. Consequently, scalability is limited and any central component in the architecture introduces a "single point of failure ". We propose a completely distributed intrusion detection system based on distributed hash tables to efficiently exchange and aggregate alerts and meta-alerts in a cooperative, self-organizing, and load-balanced way. Independent intrusion detection agents publish their alerts based on a new novelty measure for alerts which prohibits the distribution of already known and hence worthless knowledge. The benefits of our approach are evaluated for a well-known probing attack.
Keywords :
computer networks; cryptography; table lookup; computer network security; distributed hash table; distributed intrusion detection system; intrusion alert correlation; meta-alerts; Aggregates; Centralized control; Computer networks; Computer science; Information security; Intrusion detection; Mathematics; Mobile communication; Scalability; Stability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computers and Communications, 2007. ISCC 2007. 12th IEEE Symposium on
Conference_Location :
Aveiro
ISSN :
1530-1346
Print_ISBN :
978-1-4244-1520-5
Electronic_ISBN :
1530-1346
Type :
conf
DOI :
10.1109/ISCC.2007.4381564
Filename :
4381564
Link To Document :
بازگشت