A Multiple Keyword Fusion Scheme for P2P IDS Alert

  • Authors:
  • Ming Xu;Chaochi Lin;Qin Chen

  • Affiliations:
  • -;-;-

  • Venue:
  • ICINIS '08 Proceedings of the 2008 First International Conference on Intelligent Networks and Intelligent Systems
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Alert fusion is a key problem in distributed intrusion detection system (DIDS). The paper proposes a distributed intrusion alert fusion scheme based on multiple keywords and routing infrastructure: distributed hash table (DHT). All the related alerts produced by local sensor can be routed and fused to their corresponding peers by multiple keywords, while evenly distributing unrelated alerts to different peer. We evaluation our scheme with a real-world intrusion detection dataset (DShield Dataset), which has been collected firewall and NIDS logs from over 1600 administrators across the world. Experimental results show that our scheme has well scalable, and can achieve significant improvement in load balancing.