A denial-of-service resistant intrusion detection architecture

Citation
P. Mell et al., A denial-of-service resistant intrusion detection architecture, COMPUT NET, 34(4), 2000, pp. 641-658
Citations number
12
Categorie Soggetti
Information Tecnology & Communication Systems
Journal title
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING
ISSN journal
13891286 → ACNP
Volume
34
Issue
4
Year of publication
2000
Pages
641 - 658
Database
ISI
SICI code
1389-1286(200010)34:4<641:ADRIDA>2.0.ZU;2-W
Abstract
As the capabilities of intrusion detection systems (IDSs) advance, attacker s may disable organizations' IDSs before attempting to penetrate more valua ble targets. To counter this threat, we present an IDS architecture that is resistant to denial-of-service (DOS) attacks. The architecture frustrates attackers by making IDS components invisible to attackers' normal means of "seeing" in a network. Upon a successful attack, the architecture allows ID S components to relocate from attacked hosts to operational hosts thereby m itigating the attack. These capabilities are obtained by using mobile agent technology, utilizing network topology features, and by restricting the co mmunication allowed between different types of IDS components. (C) 2000 Els evier Science B.V. All rights reserved.