• DocumentCode
    2196148
  • Title

    Selective and Early Threat Detection in Large Networked Systems

  • Author

    Colajanni, Michele ; Marchetti, Mirco ; Messori, Michele

  • Author_Institution
    Dept. of Inf. Eng., Univ. of Modena & Reggio Emilia, Modena, Italy
  • fYear
    2010
  • fDate
    June 29 2010-July 1 2010
  • Firstpage
    604
  • Lastpage
    611
  • Abstract
    The complexity of modern networked information systems, as well as all the defense-in-depth best practices, require distributed intrusion detection architectures relying on the cooperation of multiple components. Similar solutions cause a multiplication of alerts, thus increasing the time needed for alert management and hiding the few critical alerts as needles in a hay stack. We propose an innovative distributed architecture for intrusion detection that is able to provide system administrators with selective and early security warnings. This architecture is suitable to large networks composed by several departments because it leverages hierarchical and peer-to-peer cooperation schemes among distributed NIDSes. Moreover, it embeds a distributed alert ranking system that makes it possible to evaluate the real level of risk represented by a security alert generated by a NIDS, and it allows independent network departments to exchange early warnings about critical threats. Thanks to these features, a system administrator can focus on the few alerts that represent a real threat for the controlled infrastructure and can be notified about the most dangerous intrusions before his department is attacked.
  • Keywords
    peer-to-peer computing; security of data; telecommunication network management; telecommunication security; alert management; distributed alert ranking system; distributed intrusion detection architectures; early security warnings; networked information systems complexity; peer-to-peer cooperation schemes; selective security warnings; system administrators; threat detection; Computer architecture; Databases; Intrusion detection; Monitoring; Servers; Software; Alert ranking; distributed IDS; early warning; intrusion detection systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
  • Conference_Location
    Bradford
  • Print_ISBN
    978-1-4244-7547-6
  • Type

    conf

  • DOI
    10.1109/CIT.2010.124
  • Filename
    5578127