• DocumentCode
    3092904
  • Title

    A Flexible and Efficient Alert Correlation Platform for Distributed IDS

  • Author

    Roschke, Sebastian ; Cheng, Feng ; Meinel, Christoph

  • Author_Institution
    Hasso Plattner Inst. (HPI), Univ. of Potsdam, Potsdam, Germany
  • fYear
    2010
  • fDate
    1-3 Sept. 2010
  • Firstpage
    24
  • Lastpage
    31
  • Abstract
    Intrusion Detection Systems (IDS) have been widely deployed in practice for detecting malicious behavior on network communication and hosts. The problem of false-positive alerts is a popular existing problem for most of IDS approaches. The solution to address this problem is correlation and clustering of alerts. To meet the practical requirements, this process needs to be finished as soon as possible, which is a challenging task as the amount of alerts produced in large scale deployments of distributed IDS is significantly high. We identify the data storage and processing algorithms to be the most important factors influencing the performance of clustering and correlation. We propose and implement the utilization of memory-supported algorithms and a column-oriented database for correlation and clustering in an extensible IDS correlation platform. The utilization of the column-oriented database, an In-Memory Alert Storage, and memory-based index tables leads to significant improvements on the performance. Different types of correlation modules can be integrated and compared on this platform. A plugin concept for Receivers provides flexible integration of various sensors and additional IDS management systems. The platform can be distributed over multiple processing units to share memory and processing power. A standardized interface is designed to provide a unified view of result reports for end users. The efficiency of the proposed platform is tested by practical experiments with several alert storage approaches, different simple algorithms, as well as local and distributed deployment.
  • Keywords
    database management systems; distributed processing; security of data; storage management; IDS management systems; alert correlation platform; column-oriented database; data storage; distributed IDS; false-positive alerts; intrusion detection systems; malicious behavior; memory-supported algorithms; network communication; processing algorithms; IDS Management; Memory-based Clustering; Memory-based Correlation; Memory-based Databases;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security (NSS), 2010 4th International Conference on
  • Conference_Location
    Melbourne, VIC
  • Print_ISBN
    978-1-4244-8484-3
  • Electronic_ISBN
    978-0-7695-4159-4
  • Type

    conf

  • DOI
    10.1109/NSS.2010.26
  • Filename
    5636110