DocumentCode
3532911
Title
A novel architecture for a computer network defense (CND) system using Content Addressable Networks (CAN)
Author
Al-Omari, D.K. ; Gurbani, Vijay K. ; Anjali, Tricha
Author_Institution
Electr. & Comput. Eng., Illinois Inst. of Technol., Chicago, IL, USA
fYear
2012
fDate
3-7 Dec. 2012
Firstpage
758
Lastpage
762
Abstract
Among the current information security prevention systems such as firewalls and intrusion detection systems, there exist several shortages such as alert overload, high false alarm rate, absence of effective alert management mechanism etc. As a result, there is a tremendous amount of alert data overload in the network, and this data could be redundant, irrelevant or meaningless. The result of this information flooding is the inability to correctly correlate the events to locate the security breach. In this paper, we aim to present the architecture of an integrated computer network defense system that is efficient, distributed and adaptable; in short, a good match for the dynamic environment of cloud computing. The use of peer-to-peer architecture is investigated for computer network defense. The architecture consists of an advanced intrusion detection system for identification of malicious traffic in such a manner that a centralized controller correlating the events is not overwhelmed by the deluge of alerts. We investigate the Content Addressable Network Distributed Hash Table for the event aggregation.
Keywords
cloud computing; file organisation; firewalls; peer-to-peer computing; CAN; CND system; alert data overload; cloud computing; computer network defense; content addressable network; distributed hash table; event aggregation; firewall; information flooding; information security prevention system; intrusion detection system; malicious traffic identification; peer-to-peer architecture; security breach; Computer architecture; Engines; Generators; Logic gates; Peer-to-peer computing; Protocols; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Globecom Workshops (GC Wkshps), 2012 IEEE
Conference_Location
Anaheim, CA
Print_ISBN
978-1-4673-4942-0
Electronic_ISBN
978-1-4673-4940-6
Type
conf
DOI
10.1109/GLOCOMW.2012.6477670
Filename
6477670
Link To Document