An Advanced IDS Management Architecture
نویسندگان
چکیده
Efficient Intrusion Detection System (IDS) management is a prominent capability for distributed IDS solutions, which makes it possible to integrate and handle different types of sensors or collect and synthesize alerts generated from multiple hosts located in a loosely coupled environment. Extensibility is the main requirement for most of IDS management systems. The concept of virtualization has been introduced into many popular IDS implementations due to the advantage on isolation and fast recovery in case of being compromised. Advanced capability for combining these newly emerged Virtual Machine (VM) based IDS approaches is another requirement for IDS management. This paper proposes an advanced IDS management architecture based on a new design of the Event Gatherer and the combination with the Virtual Machine Monitor (VMM). By implementing the known IDS standard IDMEF and a plugin concept, the Event Gatherer ensures flexibility and compatibility. Experiments are carried out to demonstrate the extensibility and virtualization-compatibility of the proposed IDS management architecture. Based on the proposed architecture, two application scenarios, IDS on Lock-Keeper and IDS in the Cloud, are realized and presented in the paper.
منابع مشابه
Towards an Integrated Intrusion Detection Monitoring in High Speed Networks
Problem statement: Security Management has become a critical aspect for large scale distributed systems. Particularly, recent Distributed Intrusion Detection Systems (DIDS) schemes in High Speed Networks (HSN) have raised new serious management problems and challenges. Increasing the effectiveness of IDS monitoring is primordial to satisfy the restrictive constraints in such large multi-domains...
متن کاملIntegrated Diagnostic System (IDS) for Aircraft Fleet Maintenance
The aim of the Integrated Diagnostic System (IDS) project is to research, develop and test advanced diagnostic and decision support tools for maintenance of complex machinery. This paper provides an overview of the hybrid reasoning conducted within this system with particular reference to Case-Based Reasoning (CBR) and its integration in this environment. The technical development of this syste...
متن کاملMOVIH-IDS: A mobile-visualization hybrid intrusion detection system
A novel hybrid artificial intelligent system for Intrusion Detection, called MOVIH-IDS, is presented in this study. A hybrid model built by means of a multiagent system that incorporates an unsupervised connectionist Intrusion Detection System (IDS) has been defined to guaranty an efficient computer network security architecture. This hybrid IDS facilitates the intrusion detection in dynamic ne...
متن کاملA Feature Selection Agent-based Ids
This paper introduces an Intrusion Detection System (IDS) based on the use of several Artificial Intelligence (AI) techniques. The anomalous detection issue is approached from a feature selection point of view, where a connectionist model is applied as a data analysis technique in an IDS. By exploiting the strengths of connectionist architectures in recognition, classification and generalizatio...
متن کاملTRINETR: An Intrusion Detection Alert Management System
TRINETR: An Intrusion Detection Alert Management and Analysis System by Jinqiao Yu Intrusion detection system (IDS) is a software system or hardware device deployed to monitor network and host activities including data flows and information accesses etc. to capture suspicious activities. In recent years, IDS has began to gain wide acceptance as a necessary and worthwhile investment on security....
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2009