loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
11th IEEE Symposium on Computers and Communications (ISCC'06)
Aggregating Distributed Sensor Data for Network Intrusion Detection
Cagliari, Sardinia, Italy
June 26-June 29
ISBN: 0-7695-2588-1
John C. McEachen, Naval Postgraduate School, USA
Cheng Kah Wai, Naval Postgraduate School, USA
Vonda L. Olsavsky, Naval Postgraduate School, USA
Distributed network intrusion detection systems which incorporate tens, hundreds, even thousands, of sensors are becoming increasing popular. Managing and presenting the information from these sensors is becoming an increasingly difficult task. This paper explores the use of Conversation Exchange Dynamics (CED) to integrate and display sensor information from multiple nodes. We present an experimental setup consisting of multiple sensors reporting individual findings to a central server for aggregated analysis. Different scenarios of network attacks and intrusions were planned to investigate the effectiveness of the distributed system. The network attacks were taken from the M.I.T Lincoln Lab 1999 Data Sets. The distributed system was subjected to different combinations of network attacks in various parts of the network. The results were then analyzed to understand the behavior of the distributed system in response to the different attacks. In general, the distributed system detected all attacks under each scenario. Some surprising observations also indicated attack responses occurring in unanticipated scenarios.
Citation:
John C. McEachen, Cheng Kah Wai, Vonda L. Olsavsky, "Aggregating Distributed Sensor Data for Network Intrusion Detection," iscc, pp.916-922, 11th IEEE Symposium on Computers and Communications (ISCC'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.