• DocumentCode
    1812352
  • Title

    A Network-Aware Distributed Membership Protocol for Collaborative Defense

  • Author

    Zage, David ; Livadas, Carl ; Schooler, Eve M.

  • Volume
    4
  • fYear
    2009
  • fDate
    29-31 Aug. 2009
  • Firstpage
    1123
  • Lastpage
    1130
  • Abstract
    To counteract current trends in network malware, distributed solutions have been developed that harness the power of collaborative end-host sensors. While these systems greatly increase the ability to defend against attack, this comes at the cost of complexity due to the coordination of distributed hosts across the dynamic network. Many previous solutions for distributed membership maintenance are agnostic to network conditions and have high overhead, making them less than ideal in the dynamic enterprise environment. In this work, we propose a network-aware, distributed membership protocol, CLUSTER, which improves the performance of the overlay system by biasing neighbor selection towards beneficial nodes based on multiple system metrics and network social patterns (of devices and their users). We provide an extensible method for aggregating and comparing multiple, possibly unrelated metrics. We demonstrate the effectiveness and utility of our protocol through simulation using real-world data and topologies. As part of our results, we highlight our analysis of node churn statistics, offering a new distribution to accurately model enterprise churn.
  • Keywords
    Internet; invasive software; software metrics; collaborative defense; dynamic enterprise environment; multiple system metrics; network malware; network-aware distributed membership protocol; Computer networks; Computer worms; Costs; Detectors; Distributed computing; International collaboration; Network topology; Peer to peer computing; Power engineering computing; Protocols; adaptivity; collaborative defense; decentralized membership; network-aware; real-world data; scalability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Science and Engineering, 2009. CSE '09. International Conference on
  • Conference_Location
    Vancouver, BC
  • Print_ISBN
    978-1-4244-5334-4
  • Electronic_ISBN
    978-0-7695-3823-5
  • Type

    conf

  • DOI
    10.1109/CSE.2009.173
  • Filename
    5283732