Distributed Self-organized Collaboration of Autonomous IDS Sensors
We present distributed self-organized model for collaboration of multiple heterogeneous IDS sensors. The adaptation model is based on a game-theoretical approach that optimizes the behavior of each IDS node with respect to other nodes in highly dynamic environment. We performed initial experimental evaluation of the proposed collaboration model on two autonomous IDS detectors deployed on different parts of university network. We show that this Intrusion Detection Network significantly improves the detection effectiveness and brings advanced defensive mechanism against novel highly sophisticated threats.
KeywordsFalse Alarm Rate Intrusion Detection Intrusion Detection Network Regret Minimization Alert Correlation
- 1.Blum, A., Mansour, Y.: Learning, regret minimization and equilibria. In: Algorithmic Game Theory, ch. 4, pp. 79–101. Cambridge University Press (2007)Google Scholar
- 2.Elshoush, H.T., Osman, I.M.: Alert correlation in collaborative intelligent intrusion detection systems–a survey. Applied Soft Computing (2011)Google Scholar
- 4.Sutton, R.S., Barto, A.G.: Reinforcement Learning: An Introduction. The MIT Press (March 1998)Google Scholar