An auto-configuration cooperative distributed intrusion detection system

Xiaoping Yang,Yu Dou
DOI: https://doi.org/10.1109/wcica.2004.1342340
2004-01-01
Abstract:To overcome some problems related to current Intrusion Detection System (IDS), such as high false negative and false positive rate, complex configuration, high cost and the inability to cooperate among components in the system, authors proposed a distributed IDS prototype. The system consists of control centers, proxies and sensors. In conjunction, authors also proposed a special communication protocol, CDIDSTP for the transparent communication between control centers and sensors via proxy. Combining carefully designed sensors and modulated IDS functions, an effective, highly auto-configurable IDS is implemented. In addition, the modulated IDS functions make the cooperation of same functional components within sensor possible.
What problem does this paper attempt to address?