• DocumentCode
    1863068
  • Title

    A framework for large-scale simulation of collaborative intrusion detection systems

  • Author

    Fisch, Dominik ; Hofmann, Alexander ; Hornik, Valentin ; Dedinski, Ivan ; Sick, Bernhard

  • Author_Institution
    Inst. of Comput. Archit., Univ. of Passau, Passau
  • fYear
    2008
  • fDate
    25-27 June 2008
  • Firstpage
    125
  • Lastpage
    130
  • Abstract
    Distributed intrusion detection and prevention play an increasingly important role in securing computer networks. In a distributed intrusion detection system, information about the current situation and knowledge about attacks are exchanged, aggregated, fused, and correlated in a cooperative manner to overcome the limitations of conventional centralized intrusion detection systems. However, this distributed approach introduces new challenges such as self-organization and efficient communication techniques. In this paper we propose a novel framework for developing, simulating, and deploying a distributed intrusion detection system that consists of several collaborating agents. The framework provides a programming interface and comprises all essential communication and synchronization methods that enables self-organized collaboration in a completely distributed manner. In two experiments we demonstrate the performance and capabilities of our implementation by simulating a large-scale worm outbreak and a one-to-many attack. Furthermore, we present two applications of our framework to show how collaboration of agents can be used to detect one-to-many attacks and how detection performance benefits from cooperation of agents.
  • Keywords
    security of data; software agents; synchronisation; collaborative intrusion detection systems; computer network security; conventional centralized intrusion detection systems; distributed intrusion detection; large-scale simulation; programming interface; self-organized collaboration; synchronization methods; Application software; Collaboration; Computational modeling; Computer architecture; Computer networks; Computer simulation; Data acquisition; Data analysis; Intrusion detection; Large-scale systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Soft Computing in Industrial Applications, 2008. SMCia '08. IEEE Conference on
  • Conference_Location
    Muroran
  • Print_ISBN
    978-1-4244-3782-5
  • Electronic_ISBN
    978-4-9904-2590-6
  • Type

    conf

  • DOI
    10.1109/SMCIA.2008.5045947
  • Filename
    5045947