Title :
SkipMon: A locality-aware Collaborative Intrusion Detection System
Author :
Emmanouil Vasilomanolakis;Matthias Kr?gl;Carlos Garcia Cordero;Max M?hlh?user;Mathias Fischer
Author_Institution :
CASED / Telecooperation Lab, Technische Universit?t Darmstadt, Germany
Abstract :
Due to the increasing quantity and sophistication of cyber-attacks, Intrusion Detection Systems (IDSs) are nowadays considered mandatory security mechanisms for protecting critical networks. Research on cyber-security is moving from such isolated IDSs towards Collaborative IDSs (CIDSs) in order to protect large-scale networks. In CIDSs, a number of IDS sensors work together for creating a holistic picture of the monitored network. Our contribution in this paper is a novel distributed and scalable CIDS, called SkipMon. Our system supports, both, the idea of locality and privacy preserving communication by means of exchanging compact alert data. Furthermore, we propose a mechanism for interconnecting sensors that experience similar traffic patterns. The experimental results suggest that our CIDS, with our technique of connecting monitoring nodes that experience similar traffic, is scalable and offers a good accuracy rate compared to a centralized system with full knowledge of the participating sensors´ data.
Keywords :
"Sensors","Monitoring","Routing","Peer-to-peer computing","Collaboration","Intrusion detection"
Conference_Titel :
Computing and Communications Conference (IPCCC), 2015 IEEE 34th International Performance
Electronic_ISBN :
2374-9628
DOI :
10.1109/PCCC.2015.7410282