• DocumentCode
    3216331
  • Title

    An Experience Improving Intrusion Detection Systems False Alarm Ratio by Using Honeypot

  • Author

    Khosravifar, Babak ; Bentahar, Jamal

  • Author_Institution
    Concordia Univ., Montreal
  • fYear
    2008
  • fDate
    25-28 March 2008
  • Firstpage
    997
  • Lastpage
    1004
  • Abstract
    When traditional firewall and intrusion detection systems (IDS) are used to detect possible attacks from the network, they often make wrong decisions and block the legitimate connections. In this paper we propose a new architecture which is composed of distributed agents and honeypot. The main focus of our approach lies in reducing the false alarm rate of the attack detection. Using the honeypot scheme, this system is able to avoid many wrong decisions made by IDS. In this system alarming adversaries, initially detected by the IDS, will be rerouted to a honeypot network for a more close investigation. If as a result of this investigation, it is found that the alarm decision made by the IDS of the agent is wrong, the connection will be guided to the original destination in order to continue the previous interaction. This action is hidden to the user. Such a scheme significantly decreases the alarm rate and provides a higher performance of IDS. In this paper the architecture of the proposed system is described, a theoretical analysis of its behavior is given and its possible extension and implementation are explained.
  • Keywords
    distributed processing; security of data; attack detection; distributed agent; false alarm rate; false alarm ratio; firewall; honeypot network; intrusion detection system; Application software; Computer architecture; Data analysis; Databases; Information analysis; Intrusion detection; Network servers; Pattern analysis; Time series analysis; Yarn;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications, 2008. AINA 2008. 22nd International Conference on
  • Conference_Location
    Okinawa
  • ISSN
    1550-445X
  • Print_ISBN
    978-0-7695-3095-6
  • Type

    conf

  • DOI
    10.1109/AINA.2008.44
  • Filename
    4482815