Trust Management and Admission Control for Host-Based Collaborative Intrusion Detection

  • Authors:
  • Carol Fung;Jie Zhang;Issam Aib;Raouf Boutaba

  • Affiliations:
  • David R. Cheriton School of Computer Science, University of Waterloo, Waterloo, Canada;School of Computer Engineering, Nanyang Technological University, Singapore, Singapore 639798;David R. Cheriton School of Computer Science, University of Waterloo, Waterloo, Canada;David R. Cheriton School of Computer Science, University of Waterloo, Waterloo, Canada

  • Venue:
  • Journal of Network and Systems Management
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

The accuracy of detecting an intrusion within a network of intrusion detection systems (IDSes) depends on the efficiency of collaboration between member IDSes. The security itself within this network is an additional concern that needs to be addressed. In this paper, we present a trust-based framework for secure and effective collaboration within an intrusion detection network (IDN). In particular, we design a trust model that allows each IDS to evaluate the trustworthiness of other IDSes based on its personal experience. We also propose an admission control algorithm for the IDS to manage the acquaintances it approaches for advice about intrusions. We discuss the effectiveness of our approach in protecting the IDN against common attacks. Additionally, experimental results demonstrate that our system yields significant improvement in detecting intrusions. The trust model further improves the robustness of the collaborative system against malicious attacks. The experimental results also support that our admission control algorithm is effective and fair, and creates incentives for collaboration.