【24h】

Collective intrusion detection in wide area networks

机译:广域网中的集体入侵检测

获取原文
获取原文并翻译 | 示例

摘要

We present in this paper a collective approach for intrusion detection in wide area networks. We use the multi-agent paradigm to model the proposed distributed system. In this system, an agent, which plays several roles, is situated on each node of the net. The first role of an agent is to perform the work of a local intrusion detection system (IDS). Periodically, it proceeds to exchange security data within its local neighbouring. The agent neighbouring consists of IDS agents of local neighbour nodes. The goal of such an approach is to consolidate the decision, regarding every suspected security event. Unlike previous works having proposed distributed systems for intrusion detection, our system is not restricted to data sharing. It proceeds in the case of a conflict to a negotiation between neighbouring agents in order to produce a consensual decision. So, the proposed system is fully distributed. It does not require any central or hierarchical control, which compromises its scalability, specially in wide area networks such as Internet. Indeed, in this kind of networks, some attacks like distributed denial of service (DDoS) require fully distributed defence. Experiments on our system show its potential for satisfactory DDoS attack detection.
机译:我们在本文中提出了一种用于广域网中入侵检测的集体方法。我们使用多主体范例对所提出的分布式系统进行建模。在此系统中,扮演多个角色的代理位于网络的每个节点上。代理程序的第一个角色是执行本地入侵检测系统(IDS)的工作。它会定期在其本地邻居之间交换安全数据。邻居代理由本地邻居节点的IDS代理组成。这种方法的目标是合并有关每个可疑安全事件的决策。与先前的工作提出了用于入侵检测的分布式系统不同,我们的系统不限于数据共享。在发生冲突的情况下,它会继续进行相邻代理之间的协商,以产生协商一致的决定。因此,所提出的系统是完全分布式的。它不需要任何中央或分级控制,这会损害其可伸缩性,尤其是在诸如Internet之类的广域网中。实际上,在这种网络中,某些攻击(如分布式拒绝服务(DDoS))需要完全分布式的防御。我们系统上的实验表明,它具有令人满意的DDoS攻击检测潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号