DocumentCode
2294561
Title
Harnessing the Power of P2P Systems for Fast Attack Signature Validation
Author
Antonatos, Spiros ; Hieu, Vu Quang
Author_Institution
Inst. of Comput. Sci., Found. for Res. & Technol. Hellas, Heraklion, Greece
fYear
2009
fDate
19-21 Oct. 2009
Firstpage
107
Lastpage
114
Abstract
Attack signature validation plays a key role in intrusion detection and prevention technologies. Usually, when new attacks, particularly worms, appear, security software analyzes and generates signatures for these attacks. Since inaccurate signatures may block legitimate traffic that is similar to the attack traffic (false positives), security software is reluctant to deploy new signatures without extensive testing. The testing procedure, however, can be time consuming, resulting in significant delays (hours or even days) in signature dissemination. To alleviate this problem, in this paper, we propose a novel architecture based on P2P technology for fast content signature validation. The basic idea is to collect and store recent network traffic at peers participating in the system in advance and use it to validate new signatures. Since the amount of traffic that needs to be checked against is huge, we also propose a high-performance validation algorithm over stored traffic data. Experimental results show that our proposed system can validate candidate attack signatures and determine potential false positives rates in just a few seconds.
Keywords
digital signatures; invasive software; peer-to-peer computing; P2P system; attack signature validation; intrusion detection; legitimate traffic; network traffic; security software; signature dissemination; software worm; Computer science; Computer security; Computer worms; Cryptography; Databases; Filters; Intrusion detection; Power system security; Telecommunication traffic; Testing; P2P defenses; indexing; signature validation;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and System Security, 2009. NSS '09. Third International Conference on
Conference_Location
Gold Coast, QLD
Print_ISBN
978-1-4244-5087-9
Electronic_ISBN
978-0-7695-3838-9
Type
conf
DOI
10.1109/NSS.2009.64
Filename
5318955
Link To Document