Research on Distributed Intrusion Detection Model Based on Information Fusion

Article Preview

Abstract:

The research actuality of Intrusion Detection System(IDS) were analyzed, Due to the defects of IDS such as high positive rate of IDS and incapable of effective detection of dispersed coordinated attacks on the time and space, the ideas of the multi-source information fusion were introduced in the paper, a multi-level IDS reasoning framework and prototype system were presented. The prototype adds analysis engine to the existing IDS Sensor, We used Bayesian Network as a tool for multi-source information fusion, and we used goal-tree to analyze the attempts of coordinated attacks and quantify the security risk of system. Compared to the existing IDS, the prototype is more integrated and more capable in finding coordinated attacks with lower false positive rate.

You might also be interested in these eBooks

Info:

Periodical:

Advanced Materials Research (Volumes 121-122)

Pages:

528-533

Citation:

Online since:

June 2010

Authors:

Export:

Price:

Permissions CCC:

Permissions PLS:

Сopyright:

© 2010 Trans Tech Publications Ltd. All Rights Reserved

Share:

Citation:

[1] Bedworth M, Brein J O. The Omnibus Model: A New Model of Data Fusion[M] . IEEE AES Systems Magazine, (2006).

Google Scholar

[2] Dasarathy B V. Fuzzy Evidential Reasoning Approach to Target Identity and State Fusion in Multi-Sensor Environments. Optical Engineering, 2007, 36(3): 669~683.

DOI: 10.1117/1.601265

Google Scholar

[3] Talreja D, Linas J, Bowman C. A framework for performance evaluation of multi target tracking systems-partII: Analysis methods. New York: University at Bufalo, (2004).

Google Scholar

[4] White G B, Fisch E A, Pooch U.W. Cooperating security managers: peer- based intrusion detection system. IEEE Network. 1996. 10(1): 20~23.

DOI: 10.1109/65.484228

Google Scholar

[5] Stephen Northcutt network intrusion detection: an analyst's handbook. New Riders Publishing, (1999).

Google Scholar

[6] Ming Yuh Huang, Robert J. Jasper. A large scale distributed intrusion detection framework based on attack strategy analysis. Computer Networks, 2005, 31. 2465~2475.

DOI: 10.1016/s1389-1286(99)00114-0

Google Scholar