• DocumentCode
    2509253
  • Title

    Aggregating Distributed Sensor Data for Network Intrusion Detection

  • Author

    McEachen, John C. ; Wai, Cheng Kah ; Olsavsky, Vonda L.

  • Author_Institution
    Naval Postgraduate School, USA
  • fYear
    2006
  • fDate
    26-29 June 2006
  • Firstpage
    916
  • Lastpage
    922
  • Abstract
    Distributed network intrusion detection systems which incorporate tens, hundreds, even thousands, of sensors are becoming increasing popular. Managing and presenting the information from these sensors is becoming an increasingly difficult task. This paper explores the use of Conversation Exchange Dynamics (CED) to integrate and display sensor information from multiple nodes. We present an experimental setup consisting of multiple sensors reporting individual findings to a central server for aggregated analysis. Different scenarios of network attacks and intrusions were planned to investigate the effectiveness of the distributed system. The network attacks were taken from the M.I.T Lincoln Lab 1999 Data Sets. The distributed system was subjected to different combinations of network attacks in various parts of the network. The results were then analyzed to understand the behavior of the distributed system in response to the different attacks. In general, the distributed system detected all attacks under each scenario. Some surprising observations also indicated attack responses occurring in unanticipated scenarios.
  • Keywords
    Computer crime; Computer networks; Computer security; Computer worms; Data security; Displays; Event detection; Intrusion detection; Network servers; Sensor systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computers and Communications, 2006. ISCC '06. Proceedings. 11th IEEE Symposium on
  • ISSN
    1530-1346
  • Print_ISBN
    0-7695-2588-1
  • Type

    conf

  • DOI
    10.1109/ISCC.2006.26
  • Filename
    1691140