Dissertation > Excellent graduate degree dissertation topics show
The GIDS of intrusion detection - based cluster technology research
Author: LuLei
Tutor: WangFeng;JiKaiFan
School: Kunming University of Science and Technology
Course: Computer Software and Theory
Keywords: Intrusion Detection Cluster System Load Balance State propagation
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 4
Quote: 0
Read: Download Dissertation
Abstract
|
With the development of computer network technology, network bandwidth grows quickly and brings more convenient network access service to users. The increasing complexity of attack means and network structure make computer network security facing more severe situation. Furthermore, computer operating system has a low defense capability in the fighting against intrusion, while firewall also lack of capability because of its passive mechanism. Intrusion detection as a dynamic network security and defense technologies, which has be the hotspot of the research on computer network security. However, the performance of the most current intrusion detection system has become the bottleneck of processing a well-loaded Gbps traffic stream. To address this problem, people try to explore ways of improving the performance of intrusion detection system, e.g. deploy custom hardware, and optimize the detection algorithm. At present load-balancing mechanism and distribute system are widely used in high-speed network intrusion detection. The traditional distributed intrusion detection systems lack of collaboration and information sharing between detection components. They fall short in providing a scalability and flexible solution.In this work, we build a cluster intrusion detection system base on GIDS. By distributing the network traffic stream over an expandable array of machines, we build a NIDS cluster which applies to high-performance environments. The system consists of front node, manager node, communication proxy node and analyzer node.Distribution Scheme is deployed on front node. Considering that, NIDS require the integrity of netflow in its detection process, we discuss different distribution schemes, and try to find a way to effective split traffic. In our prototype, we implemented a Hash-based scheme for distribution. We use Click Modular Router for the realization of front node.To build a GIDS cluster, a key challenge remains the exchange of lacking decision context. We need one certain mechanism to support states and events independent from a single GIDS instance. This paper discusses state distributing mechanism and policy controlled event management for cluster, moreover, characterize state communication, event subscription and dispatch mechanism.We introduced a flexible communication subsystem--GIDSCL. GIDSCL provides an information exchange platform between GIDS nodes. We can exchange events, policy state, and other information by GIDSCL.Finally, we thoroughly evaluate our cluster with respect to accuracy and performance. Based on our observations, we draw the conclusion that our approach provides a viable solution for multi-machine intrusion detection.
|
Related Dissertations
- Intrusion detection based on the ultrasonic echo envelope in the military security patrols,E919
- The Research and Application of Stochastic Routing in Wireless Sensor Networks,TN929.5
- Research on Intrusion Detection Technology of Wireless Sensor Networks Based on Behavior Trust,TP212.9
- Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
- The Research on Intrusion Detection System Based on Machine Learning,TP393.08
- Research and Implementation of job scheduling algorithm in the Linux cluster environment,TP301.6
- Intrusion Detection in Mobile Ad Hoc Networks: A Timed Finite State Machines Approach,TN929.5
- An Intrusion Detection System for High-Speed Networks,TP393.08
- Research on the Security in Wireless Sensor Network,TN915.08
- The Study on Joint Call Admission and Handover Control in Heterogeneous Networks,TN929.5
- Desgin and Study on Multi-node Hot-standby High Availability Cluster Software,TP311.5
- Sensitivity Analysis and Application of Orthogonal Weight Function Neural Network,TP183
- The Study of Intelligent Intrusion Detection System Based on Neural Network in Linux,TP393.08
- Petri net -based network intrusion detection system Research and Implementation,TP393.08
- FSVM -based data mining method and its application to intrusion detection research,TP393.08
- Web-based intrusion detection system logs Design and Implementation,TP393.08
- IPv4-IPv6 transition technologies CIDF Based Intrusion Detection System,TP393.08
- Intrusion detection based on data mining technology research,TP393.08
- Mechanisms based on trust metrics Research and Implementation of Intrusion Detection System,TP393.08
- Research on Parallel and Distributed Intrusion Detection Technologies,TP393.08
- Attribute Reduction Based on Rough Set and Weighted SVM intrusion detection method,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|