Fast attack detection using correlation and summarizing of security alerts in grid computing networks

  • Authors:
  • Raheel Hassan Syed;Jasmina Pazardzievska;Julien Bourgeois

  • Affiliations:
  • Computer Science Laboratory (LIFC), University of Franche-Comte (UFC), Montbeliard, France 25201;Faculty of Electrical Engineering and Information Technologies, University Ss. Cyril and Methodius, Skopje, Republic of Macedonia;Computer Science Laboratory (LIFC), University of Franche-Comte (UFC), Montbeliard, France 25201

  • Venue:
  • The Journal of Supercomputing
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Due to the extensive growth of grid computing networks, security is becoming a challenge. Usual solutions are not enough to prevent sophisticated attacks fabricated by multiple users especially when the number of nodes connected to the network is changing over the time. Attackers can use multiple nodes to launch DDoS attacks which generate a large amount of security alerts. On the one hand, this large number of security alerts degrades the overall performance of the network and creates instability in the operation of the security management solutions. On the other hand, they can help in camouflaging other real attacks. To address these issues, a correlation mechanism is proposed which reduces the security alerts and continue detecting attacks in grid computing networks. To obtain the more accurate results, a major portion of the experiments are performed by launching DDoS and Brute Force (BF) attacks in real grid environment, i.e., the Grid'5000 (G5K) network.