Dependency-based Distributed Intrusion Detection.

Ji Li, Dah-Yoh Lim,Karen R. Sollins

DETER: Proceedings of the DETER Community Workshop on Cyber Security Experimentation and Test on DETER Community Workshop on Cyber Security Experimentation and Test 2007(2007)

引用 32|浏览501
暂无评分
摘要
Distributed network intrusion detection has attracted much attention recently. Our main focus in this work is on zero-day, slow-scanning worms, of which no existing signatures are available. We organize end hosts into regions based on network knowledge, which we posit is positively correlated to the dependency structure. Leveraging on this organization, we apply different intrusion detection techniques within and across regions. We use a hidden Markov model (HMM) within a region to capture the dependency among hosts, and use sequential hypothesis testing (SHT) globally to take advantage of the independence between regions. We conduct experiments on DETER, and preliminary results show improvement on detection effectiveness and reduction of communication overhead.
更多
查看译文
关键词
detection effectiveness,different intrusion detection technique,network intrusion detection,dependency structure,network knowledge,communication overhead,end host,existing signature,hidden Markov model,main focus
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要