DocumentCode :
3108715
Title :
Performance assessment of a distributed intrusion detection system in a real network scenario
Author :
D´Antonio, Salvatore ; Formicola, Valerio ; Mazzariello, Claudio ; Oliviero, Francesco ; Romano, Simon Pietro
Author_Institution :
Dipt. delle Tecnol., Parthenope Univ. of Napoli, Napoli, Italy
fYear :
2010
fDate :
10-13 Oct. 2010
Firstpage :
1
Lastpage :
8
Abstract :
The heterogeneity and complexity of modern networks and services urge the requirement for flexible and scalable security systems, which can be dynamically configured to suit the everchanging nature of security threats and user behavior patterns. In this paper we present a distributed architecture for an Intrusion Detection System, allowing for traffic analysis at different granularity levels, performed by using the best available techniques. Such architecture leverages the principle of separation of concerns, and hence proposes to build up a system comprising entities specialized in performing different tasks, appropriately orchestrated by a broker entity playing the crucial role of the mediator. This paper stresses the point that a distributed system, besides being inherently more scalable than a centralized one, allows for better detection capabilities thanks to the effective exploitation of the inner heterogeneity of the involved detection engines. In order to support our findings, we will describe the design, implementation and deployment of the proposed solution in the framework of the INTERSECTION FP7 European Project.
Keywords :
computer network security; INTERSECTION FP7 European Project; distributed architecture; distributed intrusion detection system; performance assessment; security systems; security threats; traffic analysis; Computer architecture; Delta modulation; Engines; Intrusion detection; Measurement; Probes; Protocols; Distributed Systems; Intrusion Detection; Network security and protection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Risks and Security of Internet and Systems (CRiSIS), 2010 Fifth International Conference on
Conference_Location :
Montreal, QC
Print_ISBN :
978-1-4244-8641-0
Electronic_ISBN :
978-1-4244-8642-7
Type :
conf
DOI :
10.1109/CRISIS.2010.5764922
Filename :
5764922
Link To Document :
بازگشت