Organizations security becomes increasingly more difficult to obtain due to the fact that information technology and networking resources are dispersed across organizations. Network intrusion attacks are more and more difficult to detect even if the most sophisticated security tools are used. To address this problem, researchers and vendors have proposed alert correlation, an analysis process that takes the events produced by the monitoring components and produces compact reports on the security status of the organization under monitoring. Centralized solutions imply to gather from distributed resources by a third party the global state of the network in order to evaluate risks of attacks but neglect the honest but curious behaviors. In this paper, we focus on this issue and propose a set of solutions able to give a coarse or a fine grain global state depending on the system needs and on the privacy level requested by the involved organizations.

Benali, F., Bennani, N., Gianini, G., Cimato, S. (2010). A distributed and privacy-preserving method for network intrusion detection. In On the Move to Meaningful Internet Systems: OTM 2010 Confederated International Conferences: CoopIS, IS, DOA and ODBASE, Hersonissos, Crete, Greece, October 25-29, 1010, Proceedings, Part II (pp.861-875) [10.1007/978-3-642-16949-6_13].

A distributed and privacy-preserving method for network intrusion detection

Gianini, G;
2010

Abstract

Organizations security becomes increasingly more difficult to obtain due to the fact that information technology and networking resources are dispersed across organizations. Network intrusion attacks are more and more difficult to detect even if the most sophisticated security tools are used. To address this problem, researchers and vendors have proposed alert correlation, an analysis process that takes the events produced by the monitoring components and produces compact reports on the security status of the organization under monitoring. Centralized solutions imply to gather from distributed resources by a third party the global state of the network in order to evaluate risks of attacks but neglect the honest but curious behaviors. In this paper, we focus on this issue and propose a set of solutions able to give a coarse or a fine grain global state depending on the system needs and on the privacy level requested by the involved organizations.
paper
Bayesian Network; Information System; Intrusion Detection; Intrusion Detection System; Trusted Third Party
English
9th Confederated International Conferences on On the Move to Meaningful Internet Systems, OTM 2010: CoopIS 2010, IS 2010, DOA 2010 and ODBASE 2010 - October 25-29, 1010
2010
Meersman, R; Dillon, T; Herrero, P
On the Move to Meaningful Internet Systems: OTM 2010 Confederated International Conferences: CoopIS, IS, DOA and ODBASE, Hersonissos, Crete, Greece, October 25-29, 1010, Proceedings, Part II
9783642169489
2010
6427 LNCS
Part 2
861
875
reserved
Benali, F., Bennani, N., Gianini, G., Cimato, S. (2010). A distributed and privacy-preserving method for network intrusion detection. In On the Move to Meaningful Internet Systems: OTM 2010 Confederated International Conferences: CoopIS, IS, DOA and ODBASE, Hersonissos, Crete, Greece, October 25-29, 1010, Proceedings, Part II (pp.861-875) [10.1007/978-3-642-16949-6_13].
File in questo prodotto:
File Dimensione Formato  
Benali-2010-OTM2010-VoR.pdf

Solo gestori archivio

Tipologia di allegato: Publisher’s Version (Version of Record, VoR)
Licenza: Tutti i diritti riservati
Dimensione 315.16 kB
Formato Adobe PDF
315.16 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10281/455080
Citazioni
  • Scopus 8
  • ???jsp.display-item.citation.isi??? 3
Social impact