• DocumentCode
    3108715
  • Title

    Performance assessment of a distributed intrusion detection system in a real network scenario

  • Author

    D´Antonio, Salvatore ; Formicola, Valerio ; Mazzariello, Claudio ; Oliviero, Francesco ; Romano, Simon Pietro

  • Author_Institution
    Dipt. delle Tecnol., Parthenope Univ. of Napoli, Napoli, Italy
  • fYear
    2010
  • fDate
    10-13 Oct. 2010
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    The heterogeneity and complexity of modern networks and services urge the requirement for flexible and scalable security systems, which can be dynamically configured to suit the everchanging nature of security threats and user behavior patterns. In this paper we present a distributed architecture for an Intrusion Detection System, allowing for traffic analysis at different granularity levels, performed by using the best available techniques. Such architecture leverages the principle of separation of concerns, and hence proposes to build up a system comprising entities specialized in performing different tasks, appropriately orchestrated by a broker entity playing the crucial role of the mediator. This paper stresses the point that a distributed system, besides being inherently more scalable than a centralized one, allows for better detection capabilities thanks to the effective exploitation of the inner heterogeneity of the involved detection engines. In order to support our findings, we will describe the design, implementation and deployment of the proposed solution in the framework of the INTERSECTION FP7 European Project.
  • Keywords
    computer network security; INTERSECTION FP7 European Project; distributed architecture; distributed intrusion detection system; performance assessment; security systems; security threats; traffic analysis; Computer architecture; Delta modulation; Engines; Intrusion detection; Measurement; Probes; Protocols; Distributed Systems; Intrusion Detection; Network security and protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Risks and Security of Internet and Systems (CRiSIS), 2010 Fifth International Conference on
  • Conference_Location
    Montreal, QC
  • Print_ISBN
    978-1-4244-8641-0
  • Electronic_ISBN
    978-1-4244-8642-7
  • Type

    conf

  • DOI
    10.1109/CRISIS.2010.5764922
  • Filename
    5764922