Welcome to D
SIGMOD 2004
PODS 2004
SIGMOD RECOR
CIKM 2004
DASFAA 2004
DBPL 2003
DE-BULLETIN
DEBS 2004
<<< = DEBS'04 Pape>>>
DMKD 2004
DMSN 2004
DOLAP 2004
DPDJ 2004
EDBT 2004
ER 2003
GIS 2004
HDP 2004
HYPERTEXT 20
ICDE 2004
ICDT 2003
JCDL 2004
MDM
MIR 2004
MIS 2004
MMDB 2004
MOBIDE 2003
RIDE 2004
SBBD 2003
SIGIR FORUM
SIGIR 2004
SIGKDD EXPLO
SIGKDD 2004
SSDBM 2004
SSTD 2003
TIME 2004
TODS 2004
VLDB 2004
VLDB Journal
WEBDB 2004
WIDM 2004
XIME-P 2004
Footer

Secure Selecticast for Collaborative Intrusion Detection Systems


Philip Gross, Janak Parekh, and Gail Kaiser

  View Paper (PDF)  

Return to Security and Fault Tolerance


Abstract

The problem domain of Collaborative Intrusion Detection Systems (CIDS) introduces distinctive data routing challenges, which we show are solvable through a sufficiently flexible publish-subscribe system. In general, CIDS aim to share intrusion detection data among organizations, usually to earlier and more accurately predict impending attacks, e.g., from Internet worms that tend to attack many sites at once. In particular, participants in the CIDS collect lists of suspect IP addresses, and want to be notified if others are suspicious of the same addresses. The matching must be done efficiently and anonymously, as most organizations are reluctant to share potentially revealing information about their networks, routing alerts regarding external probes only to other CIDS participants experiencing probes from the same source(s). We term this type of simultaneous publish/subscribe selecticast. We present a potential solution using the secure Bloom filter data structure propagated over the MEET publishsubscribe framework.


©2005 Association for Computing Machinery