首页> 外文会议>2010 1st International Conference on Parallel Distributed and Grid Computing >A robust and fault-tolerant distributed intrusion detection system
【24h】

A robust and fault-tolerant distributed intrusion detection system

机译:强大且容错的分布式入侵检测系统

获取原文
获取外文期刊封面目录资料

摘要

Since it is impossible to predict and identify all the vulnerabilities of a network, and penetration into a system by malicious intruders cannot always be prevented, intrusion detection systems (IDSs) are essential entities for ensuring the security of a networked system. To be effective in carrying out their functions, the IDSs need to be accurate, adaptive, and extensible. Given these stringent requirements and the high level of vulnerabilities of the current days' networks, the design of an IDS has become a very challenging task. Although, an extensive research has been done on intrusion detection in a distributed environment, distributed IDSs suffer from a number of drawbacks e.g., high rates of false positives, low detection efficiency etc. In this paper, the design of a distributed IDS is proposed that consists of a group of autonomous and cooperating agents. In addition to its ability to detect attacks, the system is capable of identifying and isolating compromised nodes in the network thereby introducing fault-tolerance in its operations. The experiments conducted on the system have shown that it has high detection efficiency and low false positives compared to some of the currently existing systems.
机译:由于无法预测和识别网络的所有漏洞,并且无法始终防止恶意入侵者渗透到系统中,因此入侵检测系统(IDS)是确保网络系统安全的基本实体。为了有效地执行其功能,IDS必须准确,自适应且可扩展。考虑到这些严格的要求以及当今网络的高度漏洞,IDS的设计已成为一项非常具有挑战性的任务。尽管已经对分布式环境中的入侵检测进行了广泛的研究,但是分布式IDS具有许多缺点,例如误报率高,检测效率低等。在本文中,提出了一种分布式IDS的设计,由一组自治和合作代理组成。该系统除了具有检测攻击的能力外,还能够识别和隔离网络中的受感染节点,从而在其操作中引入容错功能。在该系统上进行的实验表明,与某些现有系统相比,该系统具有较高的检测效率和较低的误报率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号