DocumentCode
2915778
Title
Evaluation of a Decentralized Architecture for Large Scale Collaborative Intrusion Detection
Author
Zhou, Chenfeng Vincent ; Karunasekera, Shanika ; Leckie, Christopher
Author_Institution
Dept. of Comput. Sci. & Software Eng., Melbourne Univ., Melbourne, VIC
fYear
2007
fDate
May 21 2007-Yearly 25 2007
Firstpage
80
Lastpage
89
Abstract
An important problem in network intrusion detection is how to detect large scale coordinated attacks such as scans, worms and denial-of-service attacks. These coordinated attacks can be difficult to detect at an early stage, since the evidence of the attack may be widely distributed across different subnetworks in the Internet. A critical issue for research is how to detect these large scale attacks by correlating information from multiple intrusion detection systems in an efficient manner. Several collaborative detection systems have been proposed in the literature. However, these proposals have lacked large scale testing in real networks, and the practicalities of how to optimize the trade-off between detection accuracy and reaction time of these systems has not been demonstrated. To address these challenges, we propose LarSID, a scalable decentralized large scale intrusion detection framework. LarSID provides a service for defending against attacks by sharing potential evidence of intrusions between participant intrusion detection systems via a distributed hash table (DHT) architecture. In particular, we investigate how to optimize the trade-off between detection accuracy and reaction time of LarSID based on an analysis of a large, real-world intrusion detection dataset (DShield Dataset), which has been collected from over 1600 firewall administrators across the world. LarSID has been deployed and tested on the PlanetLab testbed, and is built on top of OpenDHT - a public DHT service. Our experimental results show significant reductions in detection latency compared to a centralized detection architecture. Currently, LarSID has been deployed on 128 PlanetLab nodes as a large scale intrusion detection service.
Keywords
Internet; cryptography; groupware; software architecture; Internet; OpenDHT; collaborative intrusion detection; decentralized architecture; distributed hash table; network intrusion detection; Collaboration; Collaborative software; Collaborative work; Computer architecture; Computer crime; Internet; Intrusion detection; Laboratories; Large-scale systems; Testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Integrated Network Management, 2007. IM '07. 10th IFIP/IEEE International Symposium on
Conference_Location
Munich
Print_ISBN
1-4244-0798-2
Electronic_ISBN
1-4244-0799-0
Type
conf
DOI
10.1109/INM.2007.374772
Filename
4258524
Link To Document