A survey of coordinated attacks and collaborative intrusion detection

A survey of coordinated attacks and collaborative intrusion detection
复制标题

DOI:
10.1016/j.cose.2009.06.008
复制
发表时间:
2010-02
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
C. Zhou;C. Leckie;S. Karunasekera
C. Zhou;C. Leckie;S. Karunasekera
中科院分区:
其他
文献类型:
--
作者:
C. Zhou;C. Leckie;S. Karunasekera

文献摘要

被引文献

相似文献

协同攻击,如大规模隐形扫描,蠕虫爆发和分布式拒绝服务(DDoS)攻击,同时发生在多个网络中。使用仅监视互联网的有限部分的孤立的入侵检测系统(IDS)来检测这样的攻击是极其困难的。在本文中,我们总结了目前的研究方向,在检测这类攻击使用协同入侵检测系统(CIDSs)。特别是,我们强调了CIDS研究中的两个主要挑战:CIDS体系结构和警报相关算法。我们回顾了目前的CIDS方法在这两个方面的挑战。最后,我们强调的机会,大规模的协作入侵检测的集成解决方案。
Coordinated attacks, such as large-scale stealthy scans, worm outbreaks and distributed denial-of-service (DDoS) attacks, occur in multiple networks simultaneously. Such attacks are extremely difficult to detect using isolated intrusion detection systems (IDSs) that monitor only a limited portion of the Internet. In this paper, we summarize the current research directions in detecting such attacks using collaborative intrusion detection systems (CIDSs). In particular, we highlight two main challenges in CIDS research: CIDS architectures and alert correlation algorithms. We review the current CIDS approaches in terms of these two challenges. We conclude by highlighting opportunities for an integrated solution to large-scale collaborative intrusion detection.