...
首页> 外文期刊>International Journal of Network Management >Detection and mitigation of monitor identification attacks in collaborative intrusion detection systems
【24h】

Detection and mitigation of monitor identification attacks in collaborative intrusion detection systems

机译:在协作入侵检测系统中检测和缓解监视器标识攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Collaborative defensive approaches such as collaborative intrusion detection system (CIDS) have emerged as a response to the continuous increase in the sophistication of cyberattacks. Such systems utilize a plethora of heterogeneous monitors to create a holistic picture of the monitored network. A number of research institutes deploy CIDSs that publish their alert data publicly over the Internet. This is important for researchers and security administrators, as such systems provide a source of real-world alert data for experimentation. However, a class of identification attacks exists, namely probe-response attacks (PRAs), which can significantly reduce the benefits of a CIDS. In particular, such attacks allow an adversary to detect the network location of the monitors of a CIDS. This article discusses the state of the art, with an emphasis on our previous and ongoing work, with regard to the detection and the mitigation of PRAs. We compare the most promising defensive mechanisms with respect to their effectiveness and the possible negative effects they might introduce to the CIDS. Finally, we provide a thorough discussion of research gaps and possible future directions for the field.
机译:协作防御方法(例如协作入侵检测系统(CIDS))应运而生,以应对网络攻击复杂性的不断提高。这样的系统利用大量的异构监视器来创建被监视网络的整体图。许多研究机构都部署了CIDS,这些CIDS通过Internet公开发布其警报数据。这对于研究人员和安全管理员而言很重要,因为此类系统提供了用于实验的真实警报数据源。但是,存在一类识别攻击,即探测响应攻击(PRA),它可能会大大降低CIDS的优势。特别是,此类攻击使对手可以检测CIDS监视器的网络位置。本文讨论了PRA的检测和缓解方面的最新技术,重点是我们之前和正在进行的工作。我们比较最有前途的防御机制的有效性以及它们可能对CIDS造成的负面影响。最后,我们对该领域的研究差距和可能的未来方向进行了详尽的讨论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号