...
首页> 外文期刊>ACM Transactions on Modeling and Computer Simulation >A Decision Support System for Placement of Intrusion Detection and Prevention Devices in Large-Scale Networks
【24h】

A Decision Support System for Placement of Intrusion Detection and Prevention Devices in Large-Scale Networks

机译:大型网络中入侵检测与防御设备放置的决策支持系统

获取原文
获取原文并翻译 | 示例
           

摘要

This article describes an innovative Decision Support System (DSS) for Placement of Intrusion Detection and Prevention Systems (PIDPS) in large-scale communication networks. PIDPS is intended to support network security personnel in optimizing the placement and configuration of malware filtering and monitoring devices within Network Service Providers' (NSP) infrastructure, and enterprise communication networks. PIDPS meshes innovative and state-of-the-art mechanisms borrowed from the domains of graph theory, epidemic modeling, and network simulation. Scalable network exploitation models enable to define the communication patterns induced by network users (thereby establishing a virtual overlay network), and parallel attack models enable a PIDPS user to define various interdependent network attacks such as: Internet worms, Trojans horses, Denial of Service (DoS) attacks, and others. PIDPS incorporates a set of deployment strategies (employing graph-theoretic centrality measures) in order to facilitate intelligent placement of filtering and monitoring devices; as well as a dedicated network simulator in order to evaluate the various deployments. Experiments with PIDPS indicate that incorporating knowledge on the overlay network (network exploitation patterns) into the placement and configuration of malware filtering and monitoring devices substantially improves the effectiveness of intrusion detection and prevention systems in NSP and enterprise networks.
机译:本文介绍了一种创新的决策支持系统(DSS),用于在大型通信网络中放置入侵检测和防御系统(PIDPS)。 PIDPS旨在支持网络安全人员优化网络服务提供商(NSP)基础架构和企业通信网络中恶意软件过滤和监视设备的放置和配置。 PIDPS结合了从图论,流行病建模和网络仿真等领域借用的创新和最先进的机制。可扩展的网络利用模型可以定义由网络用户引起的通信模式(从而建立虚拟覆盖网络),而并行攻击模型则可以使PIDPS用户定义各种相互依赖的网络攻击,例如:Internet蠕虫,特洛伊木马,拒绝服务( DoS)攻击等。 PIDPS集成了一组部署策略(采用图论中心性度量),以促进过滤和监视设备的智能放置;以及专用的网络模拟器以评估各种部署。 PIDPS的实验表明,将覆盖网络的知识(网络利用模式)整合到恶意软件过滤和监视设备的放置和配置中,可以大大提高NSP和企业网络中入侵检测和防御系统的效率。

著录项

  • 来源
  • 作者单位

    Deutsche Telekom Laboratories and the Department of Information Systems Engineering at Ben-Gurion University of the Negev, Israel;

    Deutsche Telekom Laboratories and the Department of Information Systems Engineering at Ben-Gurion University of the Negev, Israel;

    Deutsche Telekom Laboratories and the Department of Information Systems Engineering at Ben-Gurion University of the Negev, Israel;

    Ben-Gurion University and Ariel University Center of Samaria;

    Department of Computer Science, Ben-Gurion University of the Negev, Israel;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    overlay networks; intrusion detection; decision support systems;

    机译:覆盖网络;入侵检测;决策支持系统;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号