...
首页> 外文期刊>Information management & computer security >Enhancing collaborative intrusion detection networks using intrusion sensitivity in detecting pollution attacks
【24h】

Enhancing collaborative intrusion detection networks using intrusion sensitivity in detecting pollution attacks

机译:使用入侵敏感性检测污染攻击来增强协作入侵检测网络

获取原文
获取原文并翻译 | 示例

摘要

Purpose - This paper aims to propose and evaluate an intrusion sensitivity (IS)-based approach regarding the detection of pollution attacks in collaborative intrusion detection networks (CIDNs) based on the observation that each intrusion detection system may have different levels of sensitivity in detecting specific types of intrusions. Design/methodology/approach - In this work, the authors first introduce their adopted CIDN framework and a newly designed aggregation component, which aims to collect feedback, aggregate alarms and identify important alarms. The authors then describe the details of trust computation and alarm aggregation. Findings - The evaluation on the simulated pollution attacks indicates that the proposed approach is more effective in detecting malicious nodes and reducing the negative impact on alarm aggregation as compared to similar approaches. Research limitations/implications - More efforts can be made in improving the mapping of the satisfaction level, enhancing the allocation, evaluation and update of IS and evaluating the trust models in a large-scale network. Practical implications - This work investigates the effect of the proposed IS-based approach in defending against pollution attacks. The results would be of interest for security specialists in deciding whether to implement such a mechanism for enhancing CIDNs. Originality/value - The experimental results demonstrate that the proposed approach is more effective in decreasing the trust values of malicious nodes and reducing the impact of pollution attacks on the accuracy of alarm aggregation as compare to similar approaches.
机译:目的-本文旨在提出和评估一种基于入侵敏感度(IS)的方法,用于在协作入侵检测网络(CIDN)中检测污染攻击,基于以下观察结果:每个入侵检测系统在检测特定入侵检测系统时可能具有不同级别的敏感度入侵类型。设计/方法/方法-在这项工作中,作者首先介绍了他们采用的CIDN框架和新设计的聚合组件,该组件旨在收集反馈,聚合警报并识别重要警报。然后作者描述了信任计算和警报聚合的详细信息。研究结果-对模拟污染攻击的评估表明,与类似方法相比,该方法在检测恶意节点和减少对警报聚合的负面影响方面更为有效。研究局限性/意义-在大规模网络中,可以做出更多的努力来改善满意度的映射,增强IS的分配,评估和更新以及评估信任模型。实际意义-这项工作调查了基于IS的提议方法在抵御污染攻击方面的效果。该结果对于安全专家在决定是否实施这种增强CIDN的机制方面将是有意义的。原创性/价值-实验结果表明,与类似方法相比,该方法在降低恶意节点的信任值和降低污染攻击对警报聚合准确性的影响方面更为有效。

著录项

  • 来源
    《Information management & computer security 》 |2016年第3期| 265-276| 共12页
  • 作者

    Wenjuan Li; Weizhi Meng;

  • 作者单位

    Department of Computer Science, City University of Hong Kong, Hong Kong, Hong Kong;

    Department of Computer Science, City University of Hong Kong, Hong Kong, Hong Kong, and Infocomm Security Department, Institute for Infocomm Research, Singapore;

  • 收录信息 美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    CIDN; Intrusion detection; Trust computation;

    机译:CIDN;入侵检测;信任计算;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号