DocumentCode
3089542
Title
Apply data mining to defense-in-depth network security system
Author
Huang, Nen-Fu ; Kao, Chia-Nan ; Hun, Hsien-Wei ; Jai, Gin-Yuan ; Lin, Chia-Lin
Author_Institution
Dept. of Comput. Sci., National Tsing Hua Univ., Taiwan
Volume
2
fYear
2005
fDate
28-30 March 2005
Firstpage
159
Abstract
This paper proposes a defense in depth network security architecture and applies the data mining technologies to analyze the alerts collected from distributed intrusion detection and prevention systems (IDS/IPS). The proposed defense in depth architecture consists of a global policy server (GPS) to manage the scattered intrusion detection and prevention systems, each of which is managed by a local policy server (LPS). The key component of the GPS is the security information management (SIM) module where data mining technology is employed to analyze the events (alerts) collected from the LPSs. Once a DDoS attack is recognized by the SIM module, the GPS informs the LPS (IDS/IPS) to adjust the thresholds immediately to block the attack from the sources. To evaluate the effectiveness of the proposed defense in depth architecture, a prototyping is implemented, where three different data mining tools are employed. Experiment results demonstrate that for detecting the DDOS attacks, the proposed data mining-based defense in depth architecture performs very well on attack detection rate and false alarm rate.
Keywords
data mining; distributed processing; security of data; telecommunication security; DDoS attack; data mining; defense-in-depth network security system; distributed intrusion detection systems; distributed intrusion prevention systems; global policy server; local policy server; security information management; Computer crime; Data mining; Data security; Global Positioning System; Information analysis; Information management; Information security; Intrusion detection; Network servers; Scattering; Data Mining; Defense-in-depth; IDS; IPS; Network Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Information Networking and Applications, 2005. AINA 2005. 19th International Conference on
ISSN
1550-445X
Print_ISBN
0-7695-2249-1
Type
conf
DOI
10.1109/AINA.2005.118
Filename
1423668
Link To Document