• DocumentCode
    1584227
  • Title

    An efficient architecture for distributed intrusion detection system

  • Author

    Hakimi, Zahra ; Faez, Karim ; Barati, Mehdi

  • Author_Institution
    Dept. of Comput. Eng., Qazvin Islamic Azad Univ., Qazvin, Iran
  • fYear
    2013
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Due to increasing number of network attacks, it is highly crucial to equip networks with an intrusion detection system (IDS). These systems must be able to deal with today´s high speed and large scale networks. In this paper we propose a distributed IDS that performs both data capturing and data analyzing in a distributed fashion. This distributed mechanism enables our system to effectively operate within large scale and high traffic rate networks. We developed a grouping mechanism which divides computers in the network into subsets of computers with a leader and a few members. Subsequently, using a data sharing mechanism we were able to detect distributed attacks. Our data sharing mechanism added an overhead on the network traffic which is negligible compared to the overall network traffic. We simulated our method in NS2 simulation environment. Then we compared our proposed system with a centralized IDS in terms of detection rate, memory usage and packet loss rate. Results showed that our system´s performance was better despite of some extra load imposed by distribution of data processing.
  • Keywords
    computer network security; local area networks; telecommunication traffic; NS2 simulation environment; centralized IDS; computer networks; data capturie; data sharing mechanism; distributed attacks; distributed intrusion detection system; grouping mechanism; high traffic rate networks; large scale networks; network attacks; network traffic; packet loss rate; Computer architecture; Computers; Data processing; Distributed databases; IP networks; Intrusion detection; Telecommunication traffic; Centralized IDS; DARPA 1999; Distributed IDS; Intrusion detection system; NS2 simulator; Nmap; Scan attack;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security and Cryptology (ISCISC), 2013 10th International ISC Conference on
  • Conference_Location
    Yazd
  • Type

    conf

  • DOI
    10.1109/ISCISC.2013.6767356
  • Filename
    6767356