Title
A distributed and privacy-preserving method for network intrusion detection
Abstract
Organizations security becomes increasingly more difficult to obtain due to the fact that information technology and networking resources are dispersed across organizations. Network intrusion attacks are more and more difficult to detect even if the most sophisticated security tools are used. To address this problem, researchers and vendors have proposed alert correlation, an analysis process that takes the events produced by the monitoring components and produces compact reports on the security status of the organization under monitoring. Centralized solutions imply to gather from distributed resources by a third party the global state of the network in order to evaluate risks of attacks but neglect the honest but curious behaviors. In this paper, we focus on this issue and propose a set of solutions able to give a coarse or a fine grain global state depending on the system needs and on the privacy level requested by the involved organizations.
Year
DOI
Venue
2010
10.1007/978-3-642-16949-6_13
OTM Conferences (2)
Keywords
Field
DocType
network intrusion attack,security status,privacy-preserving method,alert correlation,global state,sophisticated security tool,centralized solution,monitoring component,network intrusion detection,compact report,organizations security,analysis process,information technology
Information system,Trusted third party,Network intrusion detection,Intrusion,Information technology,Computer security,Computer science,Network security,Bayesian network,Intrusion detection system
Conference
Volume
ISSN
ISBN
6427
0302-9743
3-642-16948-1
Citations 
PageRank 
References 
3
0.36
22
Authors
4
Name
Order
Citations
PageRank
Fatiha Benali1132.16
Nadia Bennani25613.91
Gabriele Gianini38113.82
Stelvio Cimato440443.64