A Generic Intrusion Detection and Diagnoser System Based on Complex Event Processing

  • Authors:
  • Massimo Ficco;Luigi Romano

  • Affiliations:
  • -;-

  • Venue:
  • CCP '11 Proceedings of the 2011 First International Conference on Data Compression, Communications and Processing
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

This work presents a generic Intrusion Detection and Diagnosis System, which implements a comprehensive alert correlation workflow for detection and diagnosis of complex intrusion scenarios in Large scale Complex Critical Infrastructures. The on-line detection and diagnosis process is based on an hybrid and hierarchical approach, which allows to detect intrusion scenarios by collecting diverse information at several architectural levels, using distributed security probes, as well as perform complex event correlation based on a Complex Event Processing Engine. The escalation process from intrusion symptoms to the identified target and cause of the intrusion is driven by a knowledge-base represented by an ontology. A prototype implementation of the proposed Intrusion Detection and Diagnosis framework is also presented.