DocumentCode :
2716679
Title :
Collaborative architecture for distributed intrusion detection system
Author :
Zaman, Safaa ; Karray, Fakhri
Author_Institution :
Dept. of Electr. & Comput. Eng., Univ. of Waterloo, Waterloo, ON, Canada
fYear :
2009
fDate :
8-10 July 2009
Firstpage :
1
Lastpage :
7
Abstract :
Due to the rapid growth of network technologies and substantial improvement in attack tools and techniques, a distributed intrusion detection system (dIDS) is required to allocate multiple IDSs across a network to monitor security events and to collect data. However, dIDS architectures suffer from many limitations such as the lack of a central analyzer and a heavy network load. In this paper, we propose a new architecture for dIDS, called a collaborative architecture for dIDS (C-dIDS), to overcome these limitations. The C-dIDS contains one-level hierarchy dIDS with a non-central analyzer. To make the detection decision for a specific IDS module in the system, this IDS module needs to collaborate with the IDS in the lower level of the hierarchy. Cooperating with lower level IDS module improves the system accuracy with less network load (just one bit of information). Moreover, by using one hierarchy level, there is no central management and processing of data so there is no chance for a single point of failure. We have examined the feasibility of our dIDS architecture by conducting several experiments using the DARPA dataset. The experimental results indicate that the proposed architecture can deliver satisfactory system performance with less network load.
Keywords :
security of data; DARPA dataset; attack tools; collaborative architecture; distributed intrusion detection system; network technologies; noncentral analyzer; one-level hierarchy dIDS; security; Collaboration; Computational intelligence; Computer architecture; Computer hacking; Computer networks; Data analysis; Information analysis; Information systems; Intrusion detection; Performance analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence for Security and Defense Applications, 2009. CISDA 2009. IEEE Symposium on
Conference_Location :
Ottawa, ON
Print_ISBN :
978-1-4244-3763-4
Electronic_ISBN :
978-1-4244-3764-1
Type :
conf
DOI :
10.1109/CISDA.2009.5356567
Filename :
5356567
Link To Document :
بازگشت