Title :
Apply data mining to defense-in-depth network security system
Author :
Huang, Nen-Fu ; Kao, Chia-Nan ; Hun, Hsien-Wei ; Jai, Gin-Yuan ; Lin, Chia-Lin
Author_Institution :
Dept. of Comput. Sci., National Tsing Hua Univ., Taiwan
Abstract :
This paper proposes a defense in depth network security architecture and applies the data mining technologies to analyze the alerts collected from distributed intrusion detection and prevention systems (IDS/IPS). The proposed defense in depth architecture consists of a global policy server (GPS) to manage the scattered intrusion detection and prevention systems, each of which is managed by a local policy server (LPS). The key component of the GPS is the security information management (SIM) module where data mining technology is employed to analyze the events (alerts) collected from the LPSs. Once a DDoS attack is recognized by the SIM module, the GPS informs the LPS (IDS/IPS) to adjust the thresholds immediately to block the attack from the sources. To evaluate the effectiveness of the proposed defense in depth architecture, a prototyping is implemented, where three different data mining tools are employed. Experiment results demonstrate that for detecting the DDOS attacks, the proposed data mining-based defense in depth architecture performs very well on attack detection rate and false alarm rate.
Keywords :
data mining; distributed processing; security of data; telecommunication security; DDoS attack; data mining; defense-in-depth network security system; distributed intrusion detection systems; distributed intrusion prevention systems; global policy server; local policy server; security information management; Computer crime; Data mining; Data security; Global Positioning System; Information analysis; Information management; Information security; Intrusion detection; Network servers; Scattering; Data Mining; Defense-in-depth; IDS; IPS; Network Security;
Conference_Titel :
Advanced Information Networking and Applications, 2005. AINA 2005. 19th International Conference on
Print_ISBN :
0-7695-2249-1
DOI :
10.1109/AINA.2005.118