Passer à la navigation principale Passer à la recherche Passer au contenu principal

An efficient and scalable intrusion detection system on logs of distributed applications

  • David Lanoë
  • , Michel Hurfin
  • , Eric Totel
  • , Carlos Maziero

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

Although security issues are now addressed during the development process of distributed applications, an attack may still affect the provided services or allow access to confidential data. To detect intrusions, we consider an anomaly detection mechanism which relies on a model of the monitored application’s normal behavior. During a model construction phase, the application is run multiple times to observe some of its correct behaviors. Each gathered trace enables the identification of significant events and their causality relationships, without requiring the existence of a global clock. The constructed model is dual: an automaton plus a list of likely invariants. The redundancy between the two sub-models decreases when generalization techniques are applied on the automaton. Solutions already proposed suffer from scalability issues. In particular, the time needed to build the model is important and its size impacts the duration of the detection phase. The proposed solutions address these problems, while keeping a good accuracy during the detection phase, in terms of false positive and false negative rates. To evaluate them, a real distributed application and several attacks against the service are considered.

langue originaleAnglais
titreICT Systems Security and Privacy Protection - 34th IFIP TC 11 International Conference, SEC 2019, Proceedings
rédacteurs en chefGurpreet Dhillon, Fredrik Karlsson, Karin Hedström, André Zúquete
EditeurSpringer New York LLC
Pages49-63
Nombre de pages15
ISBN (imprimé)9783030223113
Les DOIs
étatPublié - 1 janv. 2019
Modification externeOui
Evénement34th IFIP TC 11 International Conference on Information Security and Privacy Protection, SEC 2019 - Lisbon, Portugal
Durée: 25 juin 201927 juin 2019

Série de publications

NomIFIP Advances in Information and Communication Technology
Volume562
ISSN (imprimé)1868-4238
ISSN (Electronique)1868-422X

Une conférence

Une conférence34th IFIP TC 11 International Conference on Information Security and Privacy Protection, SEC 2019
Pays/TerritoirePortugal
La villeLisbon
période25/06/1927/06/19

Empreinte digitale

Examiner les sujets de recherche de « An efficient and scalable intrusion detection system on logs of distributed applications ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation