• DocumentCode
    2294561
  • Title

    Harnessing the Power of P2P Systems for Fast Attack Signature Validation

  • Author

    Antonatos, Spiros ; Hieu, Vu Quang

  • Author_Institution
    Inst. of Comput. Sci., Found. for Res. & Technol. Hellas, Heraklion, Greece
  • fYear
    2009
  • fDate
    19-21 Oct. 2009
  • Firstpage
    107
  • Lastpage
    114
  • Abstract
    Attack signature validation plays a key role in intrusion detection and prevention technologies. Usually, when new attacks, particularly worms, appear, security software analyzes and generates signatures for these attacks. Since inaccurate signatures may block legitimate traffic that is similar to the attack traffic (false positives), security software is reluctant to deploy new signatures without extensive testing. The testing procedure, however, can be time consuming, resulting in significant delays (hours or even days) in signature dissemination. To alleviate this problem, in this paper, we propose a novel architecture based on P2P technology for fast content signature validation. The basic idea is to collect and store recent network traffic at peers participating in the system in advance and use it to validate new signatures. Since the amount of traffic that needs to be checked against is huge, we also propose a high-performance validation algorithm over stored traffic data. Experimental results show that our proposed system can validate candidate attack signatures and determine potential false positives rates in just a few seconds.
  • Keywords
    digital signatures; invasive software; peer-to-peer computing; P2P system; attack signature validation; intrusion detection; legitimate traffic; network traffic; security software; signature dissemination; software worm; Computer science; Computer security; Computer worms; Cryptography; Databases; Filters; Intrusion detection; Power system security; Telecommunication traffic; Testing; P2P defenses; indexing; signature validation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security, 2009. NSS '09. Third International Conference on
  • Conference_Location
    Gold Coast, QLD
  • Print_ISBN
    978-1-4244-5087-9
  • Electronic_ISBN
    978-0-7695-3838-9
  • Type

    conf

  • DOI
    10.1109/NSS.2009.64
  • Filename
    5318955