DocumentCode :
2196148
Title :
Selective and Early Threat Detection in Large Networked Systems
Author :
Colajanni, Michele ; Marchetti, Mirco ; Messori, Michele
Author_Institution :
Dept. of Inf. Eng., Univ. of Modena & Reggio Emilia, Modena, Italy
fYear :
2010
fDate :
June 29 2010-July 1 2010
Firstpage :
604
Lastpage :
611
Abstract :
The complexity of modern networked information systems, as well as all the defense-in-depth best practices, require distributed intrusion detection architectures relying on the cooperation of multiple components. Similar solutions cause a multiplication of alerts, thus increasing the time needed for alert management and hiding the few critical alerts as needles in a hay stack. We propose an innovative distributed architecture for intrusion detection that is able to provide system administrators with selective and early security warnings. This architecture is suitable to large networks composed by several departments because it leverages hierarchical and peer-to-peer cooperation schemes among distributed NIDSes. Moreover, it embeds a distributed alert ranking system that makes it possible to evaluate the real level of risk represented by a security alert generated by a NIDS, and it allows independent network departments to exchange early warnings about critical threats. Thanks to these features, a system administrator can focus on the few alerts that represent a real threat for the controlled infrastructure and can be notified about the most dangerous intrusions before his department is attacked.
Keywords :
peer-to-peer computing; security of data; telecommunication network management; telecommunication security; alert management; distributed alert ranking system; distributed intrusion detection architectures; early security warnings; networked information systems complexity; peer-to-peer cooperation schemes; selective security warnings; system administrators; threat detection; Computer architecture; Databases; Intrusion detection; Monitoring; Servers; Software; Alert ranking; distributed IDS; early warning; intrusion detection systems;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
Conference_Location :
Bradford
Print_ISBN :
978-1-4244-7547-6
Type :
conf
DOI :
10.1109/CIT.2010.124
Filename :
5578127
Link To Document :
بازگشت