Framework for Evaluating Collaborative Intrusion Detection Systems
Dennis Grunewald, Joel Chinnow, Rainer Bye, Ahmet Camtepe, Sahin Albayrak
IT-Sicherheit in kollaborativen und stark vernetzten Systemen at INFORMATIK 2011 - Informatik schafft Communities
Berlin 2011
Berlin 2011
Abstract: Securing modern IT infrastructures is a challenging task because of their
increasing complexity, scale and agile nature. Monolithic approaches such as using
stand-alone firewalls and IDS devices for protecting the perimeter cannot cope with
complex malwares and multistep attacks. Collaborative security emerges as a promis-
ing approach. But, research results in collaborative security are not mature for industrial application, yet, and they require continuous evaluation and testing.
In this work, we present CIDE, a Collaborative Intrusion Detection Extension for
the network security simulation platform (NeSSi2). Built-in functionalities include
dynamic group formation based on node preferences, group-internal communication,
group management and an approach for handling the infection process for malware-
based attacks. The CIDE simulation environment provides functionalities for easy
implementation of collaborating nodes in large-scale setups. We evaluate the group
communication mechanism on the one hand and provide a case study and evaluate
our collaborative security evaluation platform in a signature exchange scenario on the
other.