Decentralized alerts correlation approach for DDoS intrusion detection

Rida Khatoun, Guillaume Doyen, Dominique Gaïti, Radwane Saad, Ahmed Serhrouchni

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Availability is one of the main characteristics of internet security and hence attacks against networks increase trying to stop services on servers. Distributed denial of service attacks are very dangerous for computer networks and services availability. Various defense systems were proposed. Unfortunately, until now, there is no efficient solution. This paper presents a decentralized architecture for an intrusion detection approach. The central point of this paper is the alert correlation among Snort intrusion detection systems (IDS). We believe that this approach optimizes the detection performance in a completely distributed fashion by relying on Pastry overlay network as indexing and routing protocol. We propose novel approach that will be improved in the future work.

Original languageEnglish
Title of host publicationProceedings of New Technologies, Mobility and Security Conference and Workshops, NTMS 2008
DOIs
Publication statusPublished - 1 Dec 2008
Externally publishedYes
EventNew Technologies, Mobility and Security Conference and Workshops, NTMS 2008 - Tangier, Morocco
Duration: 5 Nov 20087 Nov 2008

Publication series

NameProceedings of New Technologies, Mobility and Security Conference and Workshops, NTMS 2008

Conference

ConferenceNew Technologies, Mobility and Security Conference and Workshops, NTMS 2008
Country/TerritoryMorocco
CityTangier
Period5/11/087/11/08

Fingerprint

Dive into the research topics of 'Decentralized alerts correlation approach for DDoS intrusion detection'. Together they form a unique fingerprint.

Cite this