首页> 外文会议>Cyber Security in Networking Conference >A Cooperative Approach for a Global Intrusion Detection System for Internet Service Providers
【24h】

A Cooperative Approach for a Global Intrusion Detection System for Internet Service Providers

机译:互联网服务提供商全球入侵检测系统的合作方法

获取原文

摘要

Cyber-attacks have become more threatening as Internet evolves, particularly for Internet Service Providers (ISPs) that play a rule of carrying them to their subscribers. In order to protect themselves and their subscribers, ISPs invest in typical protection systems like IDS, IPS, or Firewalls, that are designed for perimeter-based operation. Even though these expensive systems are efficient to protect confined environments, they do not allow ISPs to anticipate cyber-attacks. At most, ISPs might only react to them as soon as possible to maintain network services for legitimate traffic. Based on what prior DIDS approaches have lacked, our approach relies on BGP protocol to interconnect distributed intrusion detection elements, each of which cooperating by sending information about a potential threatening flow that traverses its Autonomous System (AS). We present the architecture of our approach as well as the analytic model based on Dempster-Shafer's combination rule. The results show significant improvement in terms of reliability of the combined information, that enables better countermeasures decisions.
机译:随着互联网演变,网络攻击变得更加威胁,特别是对于互联网服务提供商(ISP)来播放将其携带到用户订阅者的规则。为了保护自己及其订阅者,ISPS投资于典型的保护系统,如ID,IPS或防火墙,这些系统被设计用于基于周边的操作。尽管这些昂贵的系统是有效保护狭窄的环境,但它们不允许ISP预测网络攻击。至多,ISPS可能只能尽快对其进行反应,以维护合法流量的网络服务。基于事先缺乏事先做的方法,我们的方法依赖于BGP协议来互连分布式入侵检测元件,每个协议通过发送关于遍历其自主系统(AS)的潜在威胁流的信息来协作。我们介绍了我们方法的架构以及基于Dempster-Shafer的组合规则的分析模型。结果表明,在合并信息的可靠性方面表现出显着的改进,这使得能够更好地对策决策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号