Complex Event Processing based Hybrid Intrusion Detection System

被引:0
作者
Mohan, Ranjan [1 ]
Vaidehi, V. [1 ]
Krishna, Ajay A. [1 ]
Mahalakshmi, M. [1 ]
Chakkaravarthy, S. Sibi [1 ]
机构
[1] Anna Univ, Madras Inst Technol, Dept Elect Engn, Madras, Tamil Nadu, India
来源
2015 3RD INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMMUNICATION AND NETWORKING (ICSCN) | 2015年
关键词
IDS; MCA; CEP; Hybrid IDS; Multivariate Correlation Analysis; Insider Threat;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Insider threats are evolving constantly and misuse the granted resource access for various malicious activities. These insider threats make use of internal network flaws as the loop holes and are the root cause for data exfiltration and infiltration (Data leakage). Organizations are devising and deploying new solutions for analyzing, monitoring and predicting these insider threats. However data leakage and network breach problems still exist and are increasing day by day. This is due to multiple root accounts, top priority privileges, shared root access, shared file system privileges etc. In this paper a new Hybrid Intrusion Detection System (IDS) is developed to overcome the above stated problem. The objective of this research is to develop a Complex Event Processing (CEP) based Hybrid IDS that integrates the output of the Host IDS and Network IDS into the CEP Module and produces a consolidated output with higher accuracy. The overall deployment protects the internal information system without any data leakage by Stateful Packet Inspection. Multivariate Correlation Analysis (MCA) is used to estimate and characterize the normal behavior of the network and send the values to the CEP Engine which alerts in case of any deviation from the normal pattern. The performance of the proposed Hybrid IDS is examined using test bed with normal and various attack scenarios.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Rule based complex event processing for an air quality monitoring system in smart city
    Kumar, Shashi Shekhar
    Chandra, Ritesh
    Agarwal, Sonali
    SUSTAINABLE CITIES AND SOCIETY, 2024, 112
  • [22] Laocoonte: An Agent Based Intrusion Detection System
    Paez, Rafael
    Torres, Miguel
    PROCEEDINGS OF THE 2009 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS, 2009, : 217 - 224
  • [23] A Hybrid Efficient Distributed Clustering Algorithm Based Intrusion Detection System to Enhance Security in MANET
    Rathish, C. R.
    Karpagavadivu, K.
    Sindhuja, P.
    Kousalya, A.
    INFORMATION TECHNOLOGY AND CONTROL, 2021, 50 (01): : 45 - 54
  • [24] Hybrid Intrusion Detection System for Enhancing the Security of a Cluster-based Wireless Sensor Network
    Yan, K. Q.
    Wang, S. C.
    Wang, S. S.
    Liu, C. W.
    PROCEEDINGS 2010 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY, (ICCSIT 2010), VOL 1, 2010, : 114 - 118
  • [25] Enhancing Security in LLNs Using a Hybrid Trust-Based Intrusion Detection System for RPL
    Remya, S.
    Pillai, Manu J.
    Arjun, C.
    Ramasubbareddy, Somula
    Cho, Yongyun
    IEEE ACCESS, 2024, 12 : 58836 - 58850
  • [26] A new hierarchical intrusion detection system based on a binary tree of classifiers
    Ahmim, Ahmed
    Zine, Nacira Ghoualmi
    INFORMATION AND COMPUTER SECURITY, 2015, 23 (01) : 31 - 57
  • [27] An intrusion detection system based on combining probability predictions of a tree of classifiers
    Ahmim, Ahmed
    Derdour, Makhlouf
    Ferrag, Mohamed Amine
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2018, 31 (09)
  • [28] Design of RFID middleware based on complex event processing
    Dong, Liang
    Wang, Dong
    Sheng, Huanye
    2006 IEEE CONFERENCE ON CYBERNETICS AND INTELLIGENT SYSTEMS, VOLS 1 AND 2, 2006, : 707 - +
  • [29] Platform based on an embedded system to evaluate the intrusion detection system
    Saber, Mohammed
    Emharref, Mohamed
    Bouchentouf, Toumi
    Benazzi, Abdelhamid
    2012 INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS (ICMCS), 2012, : 894 - 899
  • [30] Fusion of Misuse Detection with Anomaly Detection Technique for Novel Hybrid Network Intrusion Detection System
    Hussain, Jamal
    Lalmuanawma, Samuel
    RECENT DEVELOPMENTS IN INTELLIGENT COMPUTING, COMMUNICATION AND DEVICES, ICCD 2016, 2017, 555 : 73 - 87