Decentralized publish-subscribe system to prevent coordinated attacks via alert correlation

Joaquin Garcia, Fabien Autrel, Joan Borrell, Sergio Castillo, Frederic Cuppens, Guillermo Navarro

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

We present in this paper a decentralized architecture to correlate alerts between cooperative nodes in a secure multicast infrastructure. The purpose of this architecture is to detect and prevent the use of network resources to perform coordinated attacks against third party networks. By means of a cooperative scheme based on message passing, the different nodes of this system will collaborate to detect its participation on a coordinated attack and will react to avoid it. An overview of the implementation of this architecture for GNU/Linux systems will demonstrate the practicability of the system.

Original languageEnglish
Title of host publicationLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
EditorsJavier Lopez, Sihan Qing, Eiji Okamoto
PublisherSpringer Verlag
Pages223-235
Number of pages13
ISBN (Print)3540235639, 9783540235637
DOIs
Publication statusPublished - 1 Jan 2004
Externally publishedYes

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume3269
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Keywords

  • Alert Correlation
  • Intrusion Detection
  • Publish-Subscribe Systems

Fingerprint

Dive into the research topics of 'Decentralized publish-subscribe system to prevent coordinated attacks via alert correlation'. Together they form a unique fingerprint.

Cite this