Data di Pubblicazione:
2012
Citazione:
Collaborative Attack Detection Using Distributed Hash Tables / Angori, E., Colajanni, M., Marchetti, M., Messori, M. - In: Collaborative Financial Infrastructure Protection / Baldoni, Roberto; Chockler, Gregory. - STAMPA. - Berlin Heidelberg : Springer, 2012. - ISBN 9783642204197. - pp. 175-201 [10.1007/978-3-642-20420-3_9]
Abstract:
This chapter describes a distributed architecture for collaborative detection of cyber attacks and network intrusions based on distributed hash tables (DHTs). We present a high-level description of the distributed architecture for collaborative attack detection. In particular, we highlight the two main functional blocks: the collaboration layer, realized through a DHT, and the engine for complex event processing. We then describe the implementation of a working prototype of the proposed architecture that represents one of the Semantic Rooms of the CoMiFin project. Our reference implementation is implemented through well-known open source software. In particular, the DHT leverages Scribe and PAST, while we use Esper as the CEP engine. We demonstrate how the proposed implementation can be used to realize a collaborative architecture for the early detection of real-world attacks carried out against financial institutions. We focus on the detection of Man-in-the-Middle attacks to demonstrate the effectiveness of our proposal. Finally, we highlight the main advantages of the proposed architecture with respect to traditional (centralized and hierarchical) solutions for intrusion detection. In particular, we address the issues of fault tolerance, scalability, and load balancing.
Tipologia CRIS:
Capitolo/Saggio
Keywords:
Attack Detection; Distributed Hash Tables
Elenco autori:
Angori, Enrico; Colajanni, Michele; Marchetti, Mirco; Messori, Michele
Link alla scheda completa:
Titolo del libro:
Collaborative Financial Infrastructure Protection