A novel scaleable architecture for intrusion detection and mitigation in switched networks

被引:0
|
作者
Witzke, EL [1 ]
Tarman, TD [1 ]
Ghosh, S [1 ]
Woodard, G [1 ]
机构
[1] Sandia Natl Labs, Adv Networking Integrat Dept, Albuquerque, NM 87185 USA
来源
2002 MILCOM PROCEEDINGS, VOLS 1 AND 2: GLOBAL INFORMATION GRID - ENABLING TRANSFORMATION THROUGH 21ST CENTURY COMMUNICATIONS | 2002年
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
High-speed switched networks present scalability challenges to a network intrusion detection system, both in terms of the volume of data that must be analyzed, and the extent to which sensors must be inserted into the switched network to achieve comprehensive visibility. An architecture that uses a single point for intrusion assessment would quickly become overwhelmed with incoming event data from intrusion sensors that are deployed on even a moderate number of high-speed links. This is particularly true if an earnest,attack (generating many events in a short period of time) is underway. The authors propose a novel architecture that hierarchically distributes the assessment function into two assessment categories -- tactical assessment, and strategic assessment. The tactical assessment,function provides low-level event correlation and decision making,for a small sub-network (e.g:, a department LAN, an ATM switch peer group, etc.), and is capable of providing fast, real-time response when millisecond response times are required due to network attacks. The strategic assessment,function, on the other hand, implements high-level event correlation, which is useful when a larger view, of the network is required (e.g., for low intensity or distributed attacks). The tactical assessment engines interface to the strategic assessment engine by filtering and summarizing low-level events, ensuring that the strategic assessment engine's workload remains manageable. This paper describes the distributed intrusion assessment architecture in more detail, presents a few application scenarios that benefit from hierarchical attack assessment, and summarizes ongoing work in developing prototype components for this architecture.
引用
收藏
页码:395 / 399
页数:5
相关论文
共 50 条
  • [21] A Novel Node Architecture for Optical Packet-switched Networks
    Yuan Chi
    Li Zhengbin
    Xu Anshi
    2008 34TH EUROPEAN CONFERENCE ON OPTICAL COMMUNICATION (ECOC), 2008,
  • [22] A novel distributed intrusion detection architecture based on overlay multicasting
    Huang, IH
    Yang, CZ
    PARALLEL AND DISTRIBUTED COMPUTING: APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS, 2004, 3320 : 600 - 603
  • [23] A Novel SDN Dataset for Intrusion Detection in IoT Networks
    Sarica, Alper Kaan
    Angin, Pelin
    2020 16TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2020,
  • [24] An event-driven architecture for fine grained intrusion detection and attack aftermath mitigation
    Peng, Hanfeng
    Feng, Chuan
    Qiao, Haiyan
    Rozenblit, Jerzy
    ECBS 2007: 14TH ANNUAL IEEE INTERNATIONAL CONFERENCE AND WORKSHOPS ON THE ENGINEERING OF COMPUTER-BASED SYSTEMS, PROCEEDINGS: RAISING EXPECTATIONS OF COMPUTER-BASES SYSTEMS, 2007, : 55 - +
  • [25] A novel intrusion detection framework for wireless sensor networks
    Farooqi, Ashfaq Hussain
    Khan, Farrukh Aslam
    Wang, Jin
    Lee, Sungyoung
    PERSONAL AND UBIQUITOUS COMPUTING, 2013, 17 (05) : 907 - 919
  • [26] A novel intrusion detection framework for wireless sensor networks
    Ashfaq Hussain Farooqi
    Farrukh Aslam Khan
    Jin Wang
    Sungyoung Lee
    Personal and Ubiquitous Computing, 2013, 17 : 907 - 919
  • [27] Host based intrusion detection architecture for mobile ad hoc networks
    Ray, Prabhudutta
    9th International Conference on Advanced Communication Technology: Toward Network Innovation Beyond Evolution, Vols 1-3, 2007, : 1942 - 1946
  • [28] An Architecture for Wireless Intrusion Detection Systems Using Artificial Neural Networks
    da Rocha Ataide, Ricardo Luis
    Abdelouahab, Zair
    NOVEL ALGORITHMS AND TECHNIQUES IN TELECOMMUNICATIONS AND NETWORKING, 2010, : 355 - 360
  • [29] Architecture and organisation of intrusion detection and prevention systems based on Bayesian networks
    Velasevic, D
    Bulatovic, D
    CCCT 2003, VOL 1, PROCEEDINGS: COMPUTING/INFORMATION SYSTEMS AND TECHNOLOGIES, 2003, : 170 - 175
  • [30] A Kohonen SOM Architecture for Intrusion Detection on In-Vehicle Communication Networks
    Santa Barletta, Vita
    Caivano, Danilo
    Nannavecchia, Antonella
    Scalera, Michele
    APPLIED SCIENCES-BASEL, 2020, 10 (15):