Design and implementation of a decentralized prototype system for detecting distributed attacks

  • Authors:
  • Peng Ning;Sushil Jajodia;Xiaoyang Sean Wang

  • Affiliations:
  • Department of Computer Science, North Carolina State University, Raleigh, NC 27695-7535, USA;Center for Secure Information Systems, George Mason University, Fairfax, VA 22030-4444, USA;Center for Secure Information Systems, George Mason University, Fairfax, VA 22030-4444, USA

  • Venue:
  • Computer Communications
  • Year:
  • 2002

Quantified Score

Hi-index 0.24

Visualization

Abstract

This paper presents the design and implementation of a decentralized research prototype intrusion detection system (IDS) named coordinated attacks response and detection system (CARDS), which aims at detecting distributed attacks that cannot be detected using data collected at any single place. CARDS adopts a signature-based approach. It consists of three kinds of independent but cooperative components: signature manager, monitor, and directory service. Unlike traditional distributed IDSs, CARDS decomposes global representations of distributed attacks into smaller units (called detection tasks) that correspond to the distributed events indicating the attacks, and then executes and coordinates the detection tasks in the places where the corresponding events are observed.