White Papers

Secure "Selecticast" for Collaborative Intrusion Detection Systems

Category: Security

Tags: ip, data

Overview The problem domain of Collaborative Intrusion Detection Systems (CIDS) introduces distinctive data routing challenges, which the paper shows are solvable through a sufficiently flexible publish-subscribe system. CIDS share intrusion detection data among organizations, usually to predict impending attacks earlier and more accurately, e.g., from Internet worms that tend to attack many sites at once. CIDS participants collect lists of suspect IP addresses, and want to be notified if others are suspicious of the same addresses. The matching must be done efficiently and anonymously, as most organizations are reluctant to share potentially revealing information about their networks. Alerts regarding external probes should only be visible to other CIDS participants experiencing probes from the same source(s).

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Columbia University
File Format
PDF
Date Published
Jul 3, 2008
Format
White Papers
Topics
Intrusion Detection Systems, Network Security, Security Tools

Similiar White Papers

A Neural Network Based System for Intrusion Detection and Classification of Attacks

A Neural Network Based System for Intrusion Detection and Classification of Attacks

With the rapid expansion of computer networks during the past decade, security has become a crucial issue for computer s

Publisher: Queen's University  |  Tags: network

Security: New strides in preventing intrusions.

Security: New strides in preventing intrusions.

Need help eliminating risk in your IT environment? This ForwardView webshow describes how security appliances, which inc

Publisher: IBM

ATLANTIDES: An Architecture for Alert Verification in Network Intrusion Detection Systems

ATLANTIDES: An Architecture for Alert Verification in Network Intrusion Detection Systems

This paper presents an architecture1 designed for alert verification (i.e., to reduce false positives) in network intrus

Publisher: University of Twente  |  Tags: false positives, network, server

Using Artificial Intelligence in Intrusion Detection Systems

Using Artificial Intelligence in Intrusion Detection Systems

Artificial Intelligence could make the use of Intrusion Detection Systems a lot easier than it is today. They could lear

Publisher: Helsinki University of Technology

Detecting and Preventing Attacks Using Network Intrusion Detection Systems

Detecting and Preventing Attacks Using Network Intrusion Detection Systems

Intrusion detection is an important technology in business sector as well as an active area of research. It is an import

Publisher: Sathyabama University  |  Tags: information security, network

Columbia University White Papers

An Analysis of the Skype Peer-to-Peer Internet Telephony Protocol

An Analysis of the Skype Peer-to-Peer Internet Telephony Protocol

Skype is a peer-to-peer VoIP client developed by KaZaa. Skype claims that it can work almost seamlessly across NATs and

Publisher: Columbia University  |  Tags: applications, firewall, instant messaging, ip, network, peer-to-peer, voip, yahoo im

A Budget-Balanced and Price-Adaptive Credit Protocol for MANETs

A Budget-Balanced and Price-Adaptive Credit Protocol for MANETs

A virtual credit exchange protocol for Mobile Ad-hoc NETworks (MANETs) is proposed to enforce the cooperation of packet

Publisher: Columbia University  |  Tags: data, updates

Buy-at-Bulk Network Design With Protection

Buy-at-Bulk Network Design With Protection

This paper considers approximation algorithms for buy-at-bulk network design, with the additional constraint that demand

Publisher: Columbia University  |  Tags: network

Data Mining Methods for Detection of New Malicious Executables

Data Mining Methods for Detection of New Malicious Executables

A serious security threat is malicious executables, especially new, unseen malicious executables often arriving as email

Publisher: Columbia University  |  Tags: data, email

On the Detection of Signaling DoS Attacks on 3G Wireless Networks

On the Detection of Signaling DoS Attacks on 3G Wireless Networks

Third Generation (3G) wireless networks based on the CDMA2000 and UMTS standards are now increasingly being deployed thr

Publisher: Columbia University  |  Tags: cdma2000, umts, wireless networks