DocumentCode
3108715
Title
Performance assessment of a distributed intrusion detection system in a real network scenario
Author
D´Antonio, Salvatore ; Formicola, Valerio ; Mazzariello, Claudio ; Oliviero, Francesco ; Romano, Simon Pietro
Author_Institution
Dipt. delle Tecnol., Parthenope Univ. of Napoli, Napoli, Italy
fYear
2010
fDate
10-13 Oct. 2010
Firstpage
1
Lastpage
8
Abstract
The heterogeneity and complexity of modern networks and services urge the requirement for flexible and scalable security systems, which can be dynamically configured to suit the everchanging nature of security threats and user behavior patterns. In this paper we present a distributed architecture for an Intrusion Detection System, allowing for traffic analysis at different granularity levels, performed by using the best available techniques. Such architecture leverages the principle of separation of concerns, and hence proposes to build up a system comprising entities specialized in performing different tasks, appropriately orchestrated by a broker entity playing the crucial role of the mediator. This paper stresses the point that a distributed system, besides being inherently more scalable than a centralized one, allows for better detection capabilities thanks to the effective exploitation of the inner heterogeneity of the involved detection engines. In order to support our findings, we will describe the design, implementation and deployment of the proposed solution in the framework of the INTERSECTION FP7 European Project.
Keywords
computer network security; INTERSECTION FP7 European Project; distributed architecture; distributed intrusion detection system; performance assessment; security systems; security threats; traffic analysis; Computer architecture; Delta modulation; Engines; Intrusion detection; Measurement; Probes; Protocols; Distributed Systems; Intrusion Detection; Network security and protection;
fLanguage
English
Publisher
ieee
Conference_Titel
Risks and Security of Internet and Systems (CRiSIS), 2010 Fifth International Conference on
Conference_Location
Montreal, QC
Print_ISBN
978-1-4244-8641-0
Electronic_ISBN
978-1-4244-8642-7
Type
conf
DOI
10.1109/CRISIS.2010.5764922
Filename
5764922
Link To Document