Teams rather than individuals : collaborative intrusion detection


Autoria(s): Bye, Rainer; Camtepe, Seyit A.; Albayrak, Sahin
Data(s)

2010

Resumo

We propose CIMD (Collaborative Intrusion and Malware Detection), a scheme for the realization of collaborative intrusion detection approaches. We argue that teams, respectively detection groups with a common purpose for intrusion detection and response, improve the measures against malware. CIMD provides a collaboration model, a decentralized group formation and an anonymous communication scheme. Participating agents can convey intrusion detection related objectives and associated interests for collaboration partners. These interests are based on intrusion objectives and associated interests for collaboration partners. These interests are based on intrusion detection related ontology, incorporating network and hardware configurations and detection capabilities. Anonymous Communication provided by CIMD allows communication beyond suspicion, i.e. the adversary can not perform better than guessing an IDS to be the source of a message at random. The evaluation takes place with the help of NeSSi² (www.nessi2.de), the Network Security Simulator, a dedicated environment for analysis of attacks and countermeasures in mid-scale and large-scale networks. A CIMD prototype is being built based on the JIAC agent framework(www.jiac.de).

Identificador

http://eprints.qut.edu.au/58477/

Relação

http://www.dai-labor.de/fileadmin/Files/Publikationen/Buchdatei/Extended%20Abstract-Teams%20Rather%20Than%20Individuals%20Collaborative%20Intrusion%20Detection.pdf

Bye, Rainer, Camtepe, Seyit A., & Albayrak, Sahin (2010) Teams rather than individuals : collaborative intrusion detection. In 5th Security Research Conference (Future Security 2010), September 2010, Berlin.

Fonte

School of Electrical Engineering & Computer Science; Information Security Institute; Science & Engineering Faculty

Palavras-Chave #080303 Computer System Security #intrusion detection #collaboration
Tipo

Conference Item