首页> 外文会议>Cyber Security in Networking Conference >A cooperative approach for a global intrusion detection system for internet service providers
【24h】

A cooperative approach for a global intrusion detection system for internet service providers

机译:针对互联网服务提供商的全球入侵检测系统的合作方法

获取原文

摘要

Cyber-attacks have become more threatening as Internet evolves, particularly for Internet Service Providers (ISPs) that play a rule of carrying them to their subscribers. In order to protect themselves and their subscribers, ISPs invest in typical protection systems like IDS, IPS, or Firewalls, that are designed for perimeter-based operation. Even though these expensive systems are efficient to protect confined environments, they do not allow ISPs to anticipate cyber-attacks. At most, ISPs might only react to them as soon as possible to maintain network services for legitimate traffic. Based on what prior DIDS approaches have lacked, our approach relies on BGP protocol to interconnect distributed intrusion detection elements, each of which cooperating by sending information about a potential threatening flow that traverses its Autonomous System (AS). We present the architecture of our approach as well as the analytic model based on Dempster-Shafer's combination rule. The results show significant improvement in terms of reliability of the combined information, that enables better countermeasures decisions.
机译:随着Internet的发展,网络攻击已变得越来越具有威胁性,尤其是对于遵循将其携带给订户的规则的Internet服务提供商(ISP)。为了保护自己和其订户,ISP投资于典型的保护系统,例如IDS,IPS或防火墙,这些系统设计用于基于边界的操作。尽管这些昂贵的系统可以有效地保护局限性环境,但它们却不允许ISP预测网络攻击。 ISP最多只能对它们做出尽快反应,以维护合法流量的网络服务。基于先前缺少的DIDS方法,我们的方法依靠BGP协议来互连分布式入侵检测元素,每个入侵检测元素都通过发送有关穿越其自治系统(AS)的潜在威胁流的信息进行协作。我们介绍了我们的方法的架构以及基于Dempster-Shafer组合规则的分析模型。结果表明,组合信息的可靠性有了显着提高,从而可以更好地制定对策决策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号