Title :
XIDR: A Dynamic Framework Utilizing Cross-Layer Intrusion Detection for Effective Response Deployment
Author :
Svecs, Igors ; Sarkar, Tanmoy ; Basu, Samik ; Wong, Johnny S.
Author_Institution :
Dept. of Comput. Sci., Iowa State Univ., Ames, IA, USA
Abstract :
We present a complete intrusion detection and response framework named XIDR (Cross-layer Intrusion Detection and Response), which utilizes multi-source intrusion detection systems to enable cross-layer intrusion detection and cross-layer automated intrusion response system to deploy cost-effective and efficient preemptive responses. In this paper, we define the notion of cross-layer design which integrates features from various layers for detecting intrusions in wired environment, enables more fine grained detection technique and also helps us to reduce false positive and false negative rate. Moreover, cross-layer based approach for selecting and deploying response will help to deploy responses at various layers in the network. This approach will mitigate the impact of sophisticated attacks in the most efficient manner. The response selection will be preemptive as well as adaptive to the ongoing intrusion.
Keywords :
security of data; XIDR; cross-layer automated intrusion response system; cross-layer design; cross-layer intrusion detection; multisource intrusion detection systems; response deployment; Cross-layer Approach; Intrusion Detection; Intrusion Response;
Conference_Titel :
Computer Software and Applications Conference Workshops (COMPSACW), 2010 IEEE 34th Annual
Conference_Location :
Seoul
Print_ISBN :
978-1-4244-8089-0
Electronic_ISBN :
978-0-7695-4105-1
DOI :
10.1109/COMPSACW.2010.57