Efficient Distributed Signature Analysis - IFIP - Lecture Notes in Computer Science Access content directly
Conference Papers Year : 2011

Efficient Distributed Signature Analysis

Abstract

Intrusion Detection Systems (IDS) have proven as valuable measure to cope reactively with attacks in the Internet. The growing complexity of IT-systems, however, increases rapidly the audit data volumes and the size of the signature bases. This forces IDS to drop audit data in high load situations thus offering attackers chances to act undetected. To tackle this issue we propose an efficient and adaptive analysis approach for multi-step signatures that is based on a dynamic distribution of analyses. We propose different optimization strategies for an efficient analysis distribution. The strengths and weaknesses of each strategy are evaluated based on a prototype implementation.
Fichier principal
Vignette du fichier
978-3-642-21484-4_2_Chapter.pdf (296.19 Ko) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

hal-01585852 , version 1 (12-09-2017)

Licence

Attribution

Identifiers

Cite

Michael Vogel, Sebastian Schmerl, Hartmut König. Efficient Distributed Signature Analysis. 5th Autonomous Infrastructure, Management and Security (AIMS), Jun 2011, Nancy, France. pp.13-25, ⟨10.1007/978-3-642-21484-4_2⟩. ⟨hal-01585852⟩
71 View
97 Download

Altmetric

Share

Gmail Facebook X LinkedIn More