Efficient distributed signature analysis

  • Authors:
  • Michael Vogel;Sebastian Schmerl;Hartmut König

  • Affiliations:
  • Brandenburg University of Technology, Computer Science Department, Cottbus;Brandenburg University of Technology, Computer Science Department, Cottbus;Brandenburg University of Technology, Computer Science Department, Cottbus

  • Venue:
  • AIMS'11 Proceedings of the 5th international conference on Autonomous infrastructure, management, and security: managing the dynamics of networks and services
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Intrusion Detection Systems (IDS) have proven as valuable measure to cope reactively with attacks in the Internet. The growing complexity of IT-systems, however, increases rapidly the audit data volumes and the size of the signature bases. This forces IDS to drop audit data in high load situations thus offering attackers chances to act undetected. To tackle this issue we propose an efficient and adaptive analysis approach for multi-step signatures that is based on a dynamic distribution of analyses. We propose different optimization strategies for an efficient analysis distribution. The strengths and weaknesses of each strategy are evaluated based on a prototype implementation.