DocumentCode
3092904
Title
A Flexible and Efficient Alert Correlation Platform for Distributed IDS
Author
Roschke, Sebastian ; Cheng, Feng ; Meinel, Christoph
Author_Institution
Hasso Plattner Inst. (HPI), Univ. of Potsdam, Potsdam, Germany
fYear
2010
fDate
1-3 Sept. 2010
Firstpage
24
Lastpage
31
Abstract
Intrusion Detection Systems (IDS) have been widely deployed in practice for detecting malicious behavior on network communication and hosts. The problem of false-positive alerts is a popular existing problem for most of IDS approaches. The solution to address this problem is correlation and clustering of alerts. To meet the practical requirements, this process needs to be finished as soon as possible, which is a challenging task as the amount of alerts produced in large scale deployments of distributed IDS is significantly high. We identify the data storage and processing algorithms to be the most important factors influencing the performance of clustering and correlation. We propose and implement the utilization of memory-supported algorithms and a column-oriented database for correlation and clustering in an extensible IDS correlation platform. The utilization of the column-oriented database, an In-Memory Alert Storage, and memory-based index tables leads to significant improvements on the performance. Different types of correlation modules can be integrated and compared on this platform. A plugin concept for Receivers provides flexible integration of various sensors and additional IDS management systems. The platform can be distributed over multiple processing units to share memory and processing power. A standardized interface is designed to provide a unified view of result reports for end users. The efficiency of the proposed platform is tested by practical experiments with several alert storage approaches, different simple algorithms, as well as local and distributed deployment.
Keywords
database management systems; distributed processing; security of data; storage management; IDS management systems; alert correlation platform; column-oriented database; data storage; distributed IDS; false-positive alerts; intrusion detection systems; malicious behavior; memory-supported algorithms; network communication; processing algorithms; IDS Management; Memory-based Clustering; Memory-based Correlation; Memory-based Databases;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and System Security (NSS), 2010 4th International Conference on
Conference_Location
Melbourne, VIC
Print_ISBN
978-1-4244-8484-3
Electronic_ISBN
978-0-7695-4159-4
Type
conf
DOI
10.1109/NSS.2010.26
Filename
5636110
Link To Document