Cross-domain collaboration for improved IDS rule set selection. (October 2015)
- Record Type:
- Journal Article
- Title:
- Cross-domain collaboration for improved IDS rule set selection. (October 2015)
- Main Title:
- Cross-domain collaboration for improved IDS rule set selection
- Authors:
- Sonchack, John
Aviv, Adam J.
Smith, Jonathan M. - Abstract:
- Abstract: Managing an intrusion detection system (IDS) requires careful consideration of the IDS rule set used to match malicious traffic. Network operators face a tradeoff when selecting rules: a rule set that is too conservative (too few rules) could lead to network intrusion and attacks from unforeseen risks, while a rule set that is too broad (too many rules) runs the risk of increasing false alerts and diminishing network throughput. The ultimate goal is to deploy rules that are conservative but proactive, and optimizing and testing such a rule set can be time consuming and limited when considering only locally observed network traffic. We argue that automated techniques to compare feedback from multiple collaborating sources, such as collaborative filtering between networks, can improve local rule sets. Our system, ROCK (R ule setO ptimization viaC ollaborativeK nowledge), recommends network-specific, locally untested rules to network operators based on correlations between their feedback and previously submitted feedback from other operators. We evaluated ROCK in two experimental deployments to detect shellcode and in simulation to measure the effect of broad collaboration. Network operators benefitted even if they provided feedback ratings for as few as 5 rules and deployed only the top 5 rules that ROCK recommended for their network; shellcode detection rates increase by up to 150% over a local baseline with little to no impact on false alerts. Our simulationAbstract: Managing an intrusion detection system (IDS) requires careful consideration of the IDS rule set used to match malicious traffic. Network operators face a tradeoff when selecting rules: a rule set that is too conservative (too few rules) could lead to network intrusion and attacks from unforeseen risks, while a rule set that is too broad (too many rules) runs the risk of increasing false alerts and diminishing network throughput. The ultimate goal is to deploy rules that are conservative but proactive, and optimizing and testing such a rule set can be time consuming and limited when considering only locally observed network traffic. We argue that automated techniques to compare feedback from multiple collaborating sources, such as collaborative filtering between networks, can improve local rule sets. Our system, ROCK (R ule setO ptimization viaC ollaborativeK nowledge), recommends network-specific, locally untested rules to network operators based on correlations between their feedback and previously submitted feedback from other operators. We evaluated ROCK in two experimental deployments to detect shellcode and in simulation to measure the effect of broad collaboration. Network operators benefitted even if they provided feedback ratings for as few as 5 rules and deployed only the top 5 rules that ROCK recommended for their network; shellcode detection rates increase by up to 150% over a local baseline with little to no impact on false alerts. Our simulation analysis suggests that ROCK's recommendation quality increases rapidly with the number of user networks and can leverage varied degrees of similarity across networks. Our results demonstrate how security through collaboration can benefit local networks and provide proactive security in an automated way. … (more)
- Is Part Of:
- Journal of information security and applications. Volume 24/25(2015)
- Journal:
- Journal of information security and applications
- Issue:
- Volume 24/25(2015)
- Issue Display:
- Volume 24/25, Issue 2015 (2015)
- Year:
- 2015
- Volume:
- 24/25
- Issue:
- 2015
- Issue Sort Value:
- 2015-NaN-2015-0000
- Page Start:
- 25
- Page End:
- 40
- Publication Date:
- 2015-10
- Subjects:
- Network security -- Intrusion detection -- Security collaboration -- IDS -- Rule set
Computer security -- Periodicals
Information technology -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/ ↗
- DOI:
- 10.1016/j.jisa.2015.10.001 ↗
- Languages:
- English
- ISSNs:
- 2214-2126
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 176.xml