« Correlation between NetFlow System and Network Views for Intrusion Detection | Main | W32 Deloder Worm: The Building of an Army »
CARDS: A distributed system for detecting coordinated attacks
Another paper on a distributed data collection and analysis platform. Because worm outbreaks move so quickly and often semi-randomly, a distributed system makes sense: if you can aggregate the information from various disparate sensors, you may be able to detect the worm before it infects all networks.A major research problem in intrusion detection is the efficient Detection of coordinated attacks over large networks. Issues to be resolved include determining what data should be collected, which portion of the data should be analyzed, where the analysis of the data should take place, and howto correlate multi-source information. This paper proposes the architecture of a Coordinated Attack Response & Detection System (CARDS). CARDS uses a signature-based model for resolving these issues. It consists of signature managers, monitors, and directory services. The system collects data in a flexible, distributed manner, and the detection process is decentralized among various monitors and is event-driven. The paper also discusses related implementation issues.Source : CARDS: A distributed system for detecting coordinated attacks, Jiahai Yang, Peng Ning, X. Sean Wang, and Sushil Jajodia.
July 21, 2005 in detection, ids, papers | Permalink
Tell others: digg submit
|
del.icio.us this
|
Reddit
Comments
Hi to all, nice blog i just want to say hello
here!
Posted by: stefanbh | Jul 22, 2007 10:46:22 PM
gettysburg college +
Posted by: gettysburg college young | Sep 15, 2008 8:30:00 AM
mortgage goverment help from the blank loans
Posted by: loans help goverment from counter the mortgage | Oct 23, 2008 9:49:32 AM
morgage rates down
Posted by: fargo morgage rates | Dec 9, 2008 3:41:28 AM
cross and blue wellmark
Posted by: wellmark of cross blue | Jan 26, 2009 12:38:32 AM
The comments to this entry are closed.