Complex Event Processing based Hybrid Intrusion Detection System

被引:0
|
作者
Mohan, Ranjan [1 ]
Vaidehi, V. [1 ]
Krishna, Ajay A. [1 ]
Mahalakshmi, M. [1 ]
Chakkaravarthy, S. Sibi [1 ]
机构
[1] Anna Univ, Madras Inst Technol, Dept Elect Engn, Madras, Tamil Nadu, India
来源
2015 3RD INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMMUNICATION AND NETWORKING (ICSCN) | 2015年
关键词
IDS; MCA; CEP; Hybrid IDS; Multivariate Correlation Analysis; Insider Threat;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Insider threats are evolving constantly and misuse the granted resource access for various malicious activities. These insider threats make use of internal network flaws as the loop holes and are the root cause for data exfiltration and infiltration (Data leakage). Organizations are devising and deploying new solutions for analyzing, monitoring and predicting these insider threats. However data leakage and network breach problems still exist and are increasing day by day. This is due to multiple root accounts, top priority privileges, shared root access, shared file system privileges etc. In this paper a new Hybrid Intrusion Detection System (IDS) is developed to overcome the above stated problem. The objective of this research is to develop a Complex Event Processing (CEP) based Hybrid IDS that integrates the output of the Host IDS and Network IDS into the CEP Module and produces a consolidated output with higher accuracy. The overall deployment protects the internal information system without any data leakage by Stateful Packet Inspection. Multivariate Correlation Analysis (MCA) is used to estimate and characterize the normal behavior of the network and send the values to the CEP Engine which alerts in case of any deviation from the normal pattern. The performance of the proposed Hybrid IDS is examined using test bed with normal and various attack scenarios.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Complex Event Processing for Object Tracking and Intrusion Detection in Wireless Sensor Networks
    Bhargavi, R.
    Vaidehi, V.
    Bhuvaneswari, P. T. V.
    Balamuralidhar, P.
    Chandra, M. Girish
    11TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION, ROBOTICS AND VISION (ICARCV 2010), 2010, : 848 - 853
  • [2] A HYBRID INTRUSION DETECTION SYSTEM BASED ON DIFFERENTMACHINELEARNING ALGORITHMS
    Atefi, Kayvan
    Yahya, Saadiah
    Dak, Ahmad Yusri
    Atefi, Arash
    COMPUTING & INFORMATICS, 4TH INTERNATIONAL CONFERENCE, 2013, 2013, : 312 - +
  • [3] A hybrid behavioural-based cyber intrusion detection system
    Adhanom, Alemtsehay
    Melaku, Henock M.
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2019, 23 (04) : 473 - 498
  • [4] A hybrid immune intrusion detection system based on mobile agent
    Zhou, Xuanwu
    Yang, Xiaoyuan
    Wei, Ping
    Hu, Yupu
    7TH INTERNATIONAL CONFERENCE ON COMPUTER-AIDED INDUSTRIAL DESIGN & CONCEPTUAL DESIGN, 2006, : 844 - 848
  • [5] A Hybrid Approach for Intrusion Detection System
    Hariyale, Neelam
    Rathore, Manjari Singh
    Prasad, Ritu
    Saurabh, Praneet
    SOFT COMPUTING FOR PROBLEM SOLVING, SOCPROS 2018, VOL 1, 2020, 1048 : 391 - 403
  • [6] RESEARCH AND IMPLEMENTATION ON SNORT-BASED HYBRID INTRUSION DETECTION SYSTEM
    Ding, Yu-Xin
    Xiao, Min
    Liu, Ai-Wu
    PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-6, 2009, : 1414 - 1418
  • [7] Intrusion detection System based on Hybrid Whale-Genetic Algorithm
    Bilaiya, Riya
    Sharma, Rajeev Mohan
    PROCEEDINGS OF THE 2018 SECOND INTERNATIONAL CONFERENCE ON INVENTIVE COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICICCT), 2018, : 822 - 825
  • [8] Hybrid architecture for distributed intrusion detection system
    Khonde S.R.
    Venugopal U.
    Ingenierie des Systemes d'Information, 2019, 24 (01): : 19 - 28
  • [9] A Hybrid Intrusion Detection System of Cluster-based Wireless Sensor Networks
    Yan, K. Q.
    Wang, S. C.
    Liu, C. W.
    IMECS 2009: INTERNATIONAL MULTI-CONFERENCE OF ENGINEERS AND COMPUTER SCIENTISTS, VOLS I AND II, 2009, : 411 - 416
  • [10] Detection of power quality transient disturbances classification based on complex event processing
    Ma, Su-Xia
    Zhao, Yi-Di
    Ma, Ying-Long
    2ND ANNUAL INTERNATIONAL CONFERENCE ON ENERGY, ENVIRONMENTAL & SUSTAINABLE ECOSYSTEM DEVELOPMENT (EESED 2016), 2016, 115 : 460 - 465