Network Security White Papers

Secure "Selecticast" for Collaborative Intrusion Detection Systems

Overview The problem domain of Collaborative Intrusion Detection Systems (CIDS) introduces distinctive data routing challenges, which the paper shows are solvable through a sufficiently flexible publish-subscribe system. CIDS share intrusion detection data among organizations, usually to predict impending attacks earlier and more accurately, e.g., from Internet worms that tend to attack many sites at once. CIDS participants collect lists of suspect IP addresses, and want to be notified if others are suspicious of the same addresses. The matching must be done efficiently and anonymously, as most organizations are reluctant to share potentially revealing information about their networks. Alerts regarding external probes should only be visible to other CIDS participants experiencing probes from the same source(s).

Further White Paper Details
PublisherColumbia University File FormatPDF
Date PublishedJanuary 2008
FormatWhite Papers   
Topics

Quick Sitemap Links: