![]() ![]() ![]() |
![]() |
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Return to Security and Fault Tolerance The problem domain of Collaborative Intrusion Detection Systems (CIDS) introduces distinctive data routing challenges, which we show are solvable through a sufficiently flexible publish-subscribe system. In general, CIDS aim to share intrusion detection data among organizations, usually to earlier and more accurately predict impending attacks, e.g., from Internet worms that tend to attack many sites at once. In particular, participants in the CIDS collect lists of suspect IP addresses, and want to be notified if others are suspicious of the same addresses. The matching must be done efficiently and anonymously, as most organizations are reluctant to share potentially revealing information about their networks, routing alerts regarding external probes only to other CIDS participants experiencing probes from the same source(s). We term this type of simultaneous publish/subscribe selecticast. We present a potential solution using the secure Bloom filter data structure propagated over the MEET publishsubscribe framework. ![]() ©2005 Association for Computing Machinery |