...
首页> 外文期刊>International Journal of Network Management >Detection and mitigation of monitor identification attacks in collaborative intrusion detection systems
【24h】

Detection and mitigation of monitor identification attacks in collaborative intrusion detection systems

机译:None

获取原文
获取原文并翻译 | 示例
           

摘要

Collaborative defensive approaches such as collaborative intrusion detection system (CIDS) have emerged as a response to the continuous increase in the sophistication of cyberattacks. Such systems utilize a plethora of heterogeneous monitors to create a holistic picture of the monitored network. A number of research institutes deploy CIDSs that publish their alert data publicly over the Internet. This is important for researchers and security administrators, as such systems provide a source of real-world alert data for experimentation. However, a class of identification attacks exists, namely probe-response attacks (PRAs), which can significantly reduce the benefits of a CIDS. In particular, such attacks allow an adversary to detect the network location of the monitors of a CIDS. This article discusses the state of the art, with an emphasis on our previous and ongoing work, with regard to the detection and the mitigation of PRAs. We compare the most promising defensive mechanisms with respect to their effectiveness and the possible negative effects they might introduce to the CIDS. Finally, we provide a thorough discussion of research gaps and possible future directions for the field.
机译:协作防御方法,如协作入侵检测系统(CID)作为对Cyber​​Actack的复杂性持续增加的响应。这种系统利用过多的异构监测器来创建受监控网络的整体图像。许多研究机构部署CIDSS,通过互联网公开发布警报数据。这对于研究人员和安全管理员来说很重要,因为这种系统提供了实验的真实警报数据来源。然而,存在一类识别攻击,即探测响应攻击(PRA),这可以显着降低CID的益处。特别地,这种攻击允许对手检测CID的监视器的网络位置。本文讨论了最先进的国家,重点是我们之前和正在进行的工作,关于PRA的检测和缓解。我们比较关于其有效性的最有前途的防御机制以及他们可能向CID介绍的可能负面影响。最后,我们对该领域的研究差距和可能的未来方向提供了彻底的讨论。

著录项

相似文献

  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号