DocumentCode :
2294561
Title :
Harnessing the Power of P2P Systems for Fast Attack Signature Validation
Author :
Antonatos, Spiros ; Hieu, Vu Quang
Author_Institution :
Inst. of Comput. Sci., Found. for Res. & Technol. Hellas, Heraklion, Greece
fYear :
2009
fDate :
19-21 Oct. 2009
Firstpage :
107
Lastpage :
114
Abstract :
Attack signature validation plays a key role in intrusion detection and prevention technologies. Usually, when new attacks, particularly worms, appear, security software analyzes and generates signatures for these attacks. Since inaccurate signatures may block legitimate traffic that is similar to the attack traffic (false positives), security software is reluctant to deploy new signatures without extensive testing. The testing procedure, however, can be time consuming, resulting in significant delays (hours or even days) in signature dissemination. To alleviate this problem, in this paper, we propose a novel architecture based on P2P technology for fast content signature validation. The basic idea is to collect and store recent network traffic at peers participating in the system in advance and use it to validate new signatures. Since the amount of traffic that needs to be checked against is huge, we also propose a high-performance validation algorithm over stored traffic data. Experimental results show that our proposed system can validate candidate attack signatures and determine potential false positives rates in just a few seconds.
Keywords :
digital signatures; invasive software; peer-to-peer computing; P2P system; attack signature validation; intrusion detection; legitimate traffic; network traffic; security software; signature dissemination; software worm; Computer science; Computer security; Computer worms; Cryptography; Databases; Filters; Intrusion detection; Power system security; Telecommunication traffic; Testing; P2P defenses; indexing; signature validation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network and System Security, 2009. NSS '09. Third International Conference on
Conference_Location :
Gold Coast, QLD
Print_ISBN :
978-1-4244-5087-9
Electronic_ISBN :
978-0-7695-3838-9
Type :
conf
DOI :
10.1109/NSS.2009.64
Filename :
5318955
Link To Document :
بازگشت