Early Warning Intrusion Detection System
نویسندگان
چکیده
Early Warning Intrusion Detection System (EWIS) is a distributed global scoped Internet threat monitoring system with the potential of detecting large scale malicious events as early as possible. The system’s architecture includes a network of distributed low-interaction sensors and a central server [1]. The sensors are small computing platforms [2] that by design are easy to deploy in a distributed fashion to a large number of partner organizations. They are preconfigured to be robust and secure and thus integrate non-intrusively to a network infrastructure. Each sensor collects network activity flows of potentially malicious intent from dark Internet address spaces and then relays this information to the central server for logging and further analysis. The system follows the design of a Network Telescope [3] which similarly to a visual telescope, its resolution is relative to its size. As the number of deployed sensors grows, so does its resolution. EWIS’s resolution is further enhanced by deploying sensors to willing partner organizations.
منابع مشابه
Karsten Bsufka , Olaf Kroll - Peters , Sahin Albayrak : Intelligent Network - Based Early Warning Systems
In this paper we present an approach for an agent-based early warning system (A-EWS) for critical infrastructures. In our approach we combine existing security infrastructures, e.g. firewalls or intrusion detection systems, with new detection approaches to create a global view and to determine the current threat state.
متن کاملComponents for Cooperative Intrusion Detection in Dynamic Coalition Environments
We present a prototype of an Intrusion Warning System for combining event message flows of multiple domain-specific security tools in order to determine anomalies for early warning and response. Unlike other approaches for cooperating Intrusion Detection Systems (IDS), we suggest a modified star shape architecture for distributing attack information and feed back warning messages. We assume tha...
متن کاملWG Early Warning Systems
Early Warning Systems aim at detecting unclassified but potentially harmful system behavior based on preliminary indications and are complementary to Intrusion Detection Systems. Both kinds of systems try to detect, identify and react before possible damage occurs and contribute to an integrated and aggregated situation report (big picture). A particular emphasis of Early Warning Systems is to ...
متن کاملSurvey of Event Correlation Techniques for Attack Detection in Early Warning Systems
In the context of early warning systems for detecting Internet worms and other attacks, event correlation techniques are needed for two reasons. First, network attack detection is usually based on distributed sensors, e.g. intrusion detection systems. During attacks but even in normal operation, the generated amount of events is hard to handle in order to evaluate the current attack situation f...
متن کاملEarly Warning and Intrusion Detection based on Combined AI Methods
In this paper we survey the architecture and AI aspects in our project on early warningand intrusion detection based on combined AI methods. We address the problem of alarm assessment in intrusion detection and use plan reconstruction based on hierarchically organised procedural knowledge that contains descriptions of adversary actions. Reconstructed plans are supposed to correlate events and a...
متن کامل