首页> 外文会议>Computer Security Applications Conference >Collaborative Intrusion Detection System (CIDS): A Framework for Accurate and Efficient IDS
【24h】

Collaborative Intrusion Detection System (CIDS): A Framework for Accurate and Efficient IDS

机译:协作入侵检测系统(CIDS):一种准确和高效的ID框架

获取原文
获取外文期刊封面目录资料

摘要

In this paper, we present the design and implementation of a Collaborative Intrusion Detection System (CIDS) for accurate and efficient intrusion detection in a distributed system. CIDS employs multiple specialized detectors at the different layers - network, kernel and application - and a manager based framework for aggregating the alarms from the different detectors to provide a combined alarm for an intrusion. The premise is that a carefully designed and configured CIDS can increase the accuracy of detection compared to individual detectors, without a substantial degradation in performance. In order to validate the premise, we present the design and implementation of a CIDS which employs Snort, Libsafe, and a new kernel level IDS called Sysmon. The manager has a graph-based and a Bayesian network based aggregation method for combining the alarms to finally come up with a decision about the intrusion. The system is evaluated using a web-based electronic store front application and under three different classes of attacks - buffer overflow, flooding and script-based attacks. The results show performance degradations compared to no detection of 3.9% and 6.3% under normal workload and a buffer overflow attack respectively. The experiments to evaluate the accuracy of the system show that the normal workload generates false alarms for Snort and the elementary detectors produce missed alarms. CIDS does not flag the false alarm and reduces the incidence of missed alarms to 1 of the 7 cases. CIDS can also be used to measure the propagation time of an intrusion which is useful in choosing an appropriate response strategy.
机译:在本文中,我们介绍了用于在分布式系统中进行精确高效的入侵检测的协同入侵检测系统(CID)的设计和实现。 CIDS在不同的层次使用多个专用探测器 - 网络,内核和应用程序 - 以及基于管理器的管理员,用于将来自不同检测器的警报聚合,以提供用于入侵的组合警报。前提是精心设计和配置的CID可以增加与单个探测器相比检测的准确性,而无需在性能方面的显着降级。为了验证前提,我们介绍了使用snort,libsafe和一个名为sysmon的新内核级别ID的CID的设计和实现。经理具有基于图形的基于图形的基于贝叶斯网络的聚合方法,用于将警报结合到最后提出了关于侵入的决定。使用基于Web的电子商店前应用程序和三种不同的攻击类别进行评估系统 - 缓冲溢出,洪水和基于脚本的攻击。结果表明,在正常工作量下没有检测到3.9%和6.3%的检测和缓冲区溢出攻击相比。评估系统准确性的实验表明,正常工作负载为SNORT产生误报,并且基本探测器产生错过的警报。 CIDS不会标记错误警报,并将错过警报的入射降低到7例中的1个。 CID也可用于测量入侵的传播时间,这对于选择适当的响应策略是有用的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号