Research on Object-Storage-Based Intrusion Detection

  • Authors:
  • Youhui Zhang;Dongsheng Wang

  • Affiliations:
  • Tsinghua University, China;Tsinghua University, China

  • Venue:
  • ICPADS '06 Proceedings of the 12th International Conference on Parallel and Distributed Systems - Volume 1
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Storage-based intrusion detection systems (IDS) can be valuable tools in monitoring for the intrusion on a host computer. However, because the traditional storage device works on the block-level while intrusion always happens on the file-level, this gap has to be erased by detection software, which is a hard and time-consuming task. To solve this problem and to accord with the trend of moving more processing power into storage, this paper presents a novel idea to design an IDS on object-based storage devices (OSD), and analyzes how the features of OSD can be used for intrusion detection (ID) and for violation responding. Moreover, the existing OSD standard is enhanced to own the new functions. Compared with the existing research on block-level storage devices, OSD-based ID is more straightforward for implementation. We build such a prototype based on the OSD reference implementation provided by Intel. Testing results show that the extra overhead introduced by ID is acceptable.