首页> 外文会议>IEEE International Performance Computing and Communications Conference >SkipMon: A locality-aware Collaborative Intrusion Detection System
【24h】

SkipMon: A locality-aware Collaborative Intrusion Detection System

机译:SkipMon:一种可感知位置的协作入侵检测系统

获取原文

摘要

Due to the increasing quantity and sophistication of cyber-attacks, Intrusion Detection Systems (IDSs) are nowadays considered mandatory security mechanisms for protecting critical networks. Research on cyber-security is moving from such isolated IDSs towards Collaborative IDSs (CIDSs) in order to protect large-scale networks. In CIDSs, a number of IDS sensors work together for creating a holistic picture of the monitored network. Our contribution in this paper is a novel distributed and scalable CIDS, called SkipMon. Our system supports, both, the idea of locality and privacy preserving communication by means of exchanging compact alert data. Furthermore, we propose a mechanism for interconnecting sensors that experience similar traffic patterns. The experimental results suggest that our CIDS, with our technique of connecting monitoring nodes that experience similar traffic, is scalable and offers a good accuracy rate compared to a centralized system with full knowledge of the participating sensors' data.
机译:由于网络攻击的数量和复杂性不断增加,如今入侵检测系统(IDS)被认为是用于保护关键网络的强制性安全机制。为了保护大规模网络,网络安全研究正在从这种孤立的IDS转向协作IDS(CIDS)。在CIDS中,许多IDS传感器一起工作以创建被监视网络的整体图。我们在本文中所做的贡献是一种新颖的分布式可扩展CIDS,称为SkipMon。我们的系统通过交换紧凑的警报数据来支持本地性和隐私保护通信的思想。此外,我们提出了一种用于互连经历类似流量模式的传感器的机制。实验结果表明,与集中了解参与的传感器数据的集中式系统相比,我们的CIDS通过连接经历类似流量的监视节点的技术,具有可伸缩性,并且具有较高的准确率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号