Intrusion detection and security policy framework for distributed environments

A. A. E. Kalam, Jérémy Briffaut, C. Toinard, M. Blanc
{"title":"Intrusion detection and security policy framework for distributed environments","authors":"A. A. E. Kalam, Jérémy Briffaut, C. Toinard, M. Blanc","doi":"10.1109/ISCST.2005.1553300","DOIUrl":null,"url":null,"abstract":"This paper presents a novel intrusion detection approach and a new infrastructure to enforce the security policy within a distributed system. The solution guarantees the consistency of the security policy and prevents any accidental or malicious update (of the local policies). The control is carried out locally (in each host) in accordance with a meta-policy that enables a distributed control to update a global security policy while satisfying global security properties. The solution is more robust in terms of fault-tolerance and resists to denial of service attacks since the solutions carries out all the control locally. Two levels of intrusion detection are proposed to guaranty the integrity and the consistency of the distributed policy. The first level (meta-level, or administration level) guarantees that each local policy evolves according to the global security properties. This level detects attacks trying inadequate alterations of the local security policies. The second level corresponds to a classical intrusion detection system. But, it can take advantages of the local policy to detect attacks that violate the security objectives. That second level enables to integrate and to adjust various classical IDS. Our approach enforces the security of large scale systems","PeriodicalId":283620,"journal":{"name":"Proceedings of the 2005 International Symposium on Collaborative Technologies and Systems, 2005.","volume":"30 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-05-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2005 International Symposium on Collaborative Technologies and Systems, 2005.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISCST.2005.1553300","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

This paper presents a novel intrusion detection approach and a new infrastructure to enforce the security policy within a distributed system. The solution guarantees the consistency of the security policy and prevents any accidental or malicious update (of the local policies). The control is carried out locally (in each host) in accordance with a meta-policy that enables a distributed control to update a global security policy while satisfying global security properties. The solution is more robust in terms of fault-tolerance and resists to denial of service attacks since the solutions carries out all the control locally. Two levels of intrusion detection are proposed to guaranty the integrity and the consistency of the distributed policy. The first level (meta-level, or administration level) guarantees that each local policy evolves according to the global security properties. This level detects attacks trying inadequate alterations of the local security policies. The second level corresponds to a classical intrusion detection system. But, it can take advantages of the local policy to detect attacks that violate the security objectives. That second level enables to integrate and to adjust various classical IDS. Our approach enforces the security of large scale systems
分布式环境的入侵检测和安全策略框架
本文提出了一种新的入侵检测方法和一种在分布式系统中实施安全策略的基础结构。该解决方案既保证了安全策略的一致性,又防止了(本地策略的)意外更新或恶意更新。控制是根据元策略在本地(在每个主机中)执行的,元策略使分布式控制能够在满足全局安全属性的同时更新全局安全策略。该解决方案在容错和抵抗拒绝服务攻击方面更加健壮,因为该解决方案在本地执行所有控制。为了保证分布式策略的完整性和一致性,提出了两级入侵检测。第一级(元级或管理级)保证每个本地策略根据全局安全属性发展。此级别检测试图对本地安全策略进行不适当更改的攻击。第二层对应于经典的入侵检测系统。但是,它可以利用本地策略来检测违反安全目标的攻击。第二个级别允许集成和调整各种经典IDS。我们的方法加强了大规模系统的安全性
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信