A Hierarchical Architecture and Probabilistic Strategy for Collaborative Intrusion Detection

被引:6
|
作者
Hardegen, Christoph [1 ]
Petersen, Mike [1 ]
Ezelu, Chukwuebuka [1 ]
Geier, Timo [1 ]
Rieger, Sebastian [1 ]
Buehler, Ulrich [1 ]
机构
[1] Fulda Univ Appl Sci, Dept Appl Comp Sci, Fulda, Germany
关键词
Collaborative Intrusion Detection; Hierarchical Architecture; Probabilistic Classification Strategy; Network Flows; NETWORK; OVERLAY;
D O I
10.1109/CNS53000.2021.9705027
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Large-scale network attacks like (distributed) denial of service or probing/port scanning are performed in a (highly) distributed and coordinated manner to increase their volume and velocity. Since systems from multiple infrastructures are involved while either being used as attack source or targeted as destination, local scopes w.r.t. observed network data can be combined to extract or derive comprehensive knowledge for attack detection at a global level. To support this, a three-tier hierarchical architecture for collaborative intrusion detection and a probabilistic classification strategy for flow data that leverages the architecture for local and especially global collaboration are proposed in this paper. While the benefits of the approach depend on the considered attack type and may vary for participating networks, experiments reveal that the CIDS hierarchy is advantageous compared to other intrusion detection deployments w.r.t. achieved accuracy scores and shared data volume.
引用
收藏
页码:128 / 136
页数:9
相关论文
共 50 条
  • [1] Probabilistic inference strategy in distributed intrusion detection systems
    Ding, JG
    Xu, SH
    Krämer, B
    Bai, YC
    Chen, HS
    Zhang, J
    PARALLEL AND DISTRIBUTED PROCESSING AND APPLICATIONS, PROCEEDINGS, 2004, 3358 : 835 - 844
  • [2] An Architecture for Federated Learning Enabled Collaborative Intrusion Detection Systems
    McOsker, Caitlin
    Handlin, Michael
    Li, Lei
    Shahriar, Hossain
    Zho, Liang
    DIGITAL INNOVATION AND ENTREPRENEURSHIP (AMCIS 2021), 2021,
  • [3] Evaluation of a decentralized architecture for large scale collaborative intrusion detection
    Zhou, Chenfeng Vincent
    Karunasekera, Shanika
    Leckie, Christopher
    2007 10TH IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2009), VOLS 1 AND 2, 2007, : 80 - +
  • [4] A Distributed and Collaborative Intrusion Detection Architecture for Wireless Mesh Networks
    Anderson Morais
    Ana Cavalli
    Mobile Networks and Applications, 2014, 19 : 101 - 120
  • [5] A Distributed and Collaborative Intrusion Detection Architecture for Wireless Mesh Networks
    Morais, Anderson
    Cavalli, Ana
    MOBILE NETWORKS & APPLICATIONS, 2014, 19 (01): : 101 - 120
  • [6] CHFL: A Collaborative Hierarchical Federated Intrusion Detection System for Vehicular Networks
    Mirzaee, Parya Haji
    Shojafar, Mohammad
    Cruickshank, Haitham
    Tafazolli, Rahim
    2022 27TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2022), 2022,
  • [7] New Collaborative Intrusion Detection Architecture Based on Multi Agent Systems
    El Ajjouri, Mohssine
    Benhadou, Siham
    Medromi, Hicham
    2015 INTERNATIONAL CONFERENCE ON WIRELESS NETWORKS AND MOBILE COMMUNICATIONS (WINCOM), 2015, : 241 - 246
  • [8] A nifty collaborative intrusion detection and prevention architecture for Smart Grid ecosystems
    Patel, Ahmed
    Alhussian, Hitham
    Pedersen, Jens Myrup
    Bounabat, Bouchaib
    Celestino Junior, Joaquim
    Katsikas, Sokratis
    COMPUTERS & SECURITY, 2017, 64 : 92 - 109
  • [9] Peer-to-Peer Architecture for Collaborative Intrusion and Malware Detection on a Large Scale
    Marchetti, Mirco
    Messori, Michele
    Colajanni, Michele
    INFORMATION SECURITY, PROCEEDINGS, 2009, 5735 : 475 - 490
  • [10] TRINETR: An architecture for collaborative intrusion detection and knowledge-based alert evaluation
    Yu, JQ
    Reddy, YVR
    Selliah, S
    Reddy, S
    Bharadwaj, V
    Kankanahalli, S
    ADVANCED ENGINEERING INFORMATICS, 2005, 19 (02) : 93 - 101