About

Log in?

DTU users get better search results including licensed content and discounts on order fees.

Anyone can log in and get personalized features such as favorites, tags and feeds.

Log in as DTU user Log in as non-DTU user No thanks

DTU Findit

Conference paper

Enhancing Challenge-based Collaborative Intrusion Detection against Insider Attacks using Spatial Correlation

In Proceedings of 2021 Ieee Conference on Dependable and Secure Computing — 2021, pp. 1-8
From

Guangzhou University1

Department of Applied Mathematics and Computer Science, Technical University of Denmark2

Cyber Security, Department of Applied Mathematics and Computer Science, Technical University of Denmark3

University of Texas at San Antonio4

With cyber-attacks becoming more complicated and the networks increasingly interconnected, there has been a move towards using collaborative intrusion detection networks (CIDNs) to identify cyber-threats more effectively. However, insider attacks may remain challenging to mitigate in CIDNs, as the intruders are able to control one or more internal nodes.

Challenge- based trust mechanism is one promising solution to help safeguard CIDNs against common insider attacks, but not necessarily against advanced attacks such as passive message fingerprint attacks. In this work, we focus on challenge-based trust mechanism and advocate that considering additional level of trust can enhance the robustness of CIDNs.

Specifically, we design an enhanced trust management scheme by checking spatial correlation among nodes' behavior, regarding forwarding delay, packet dropping and sending rate. Then, we evaluate our approach in a simulated environment, as well as a realworld environment in collaboration with an IT organization.

Experimental results demonstrate that our approach can help enhance the robustness of challenge-based trust mechanism by detecting malicious nodes faster than similar approaches (i.e., reducing time consumption by two to three days).

Language: English
Publisher: IEEE
Year: 2021
Pages: 1-8
Proceedings: 2021 IEEE Conference on Dependable and Secure Computing
ISBN: 1728175348 , 1728175356 , 9781728175348 and 9781728175355
Types: Conference paper
DOI: 10.1109/DSC49826.2021.9346232
ORCIDs: Meng, Weizhi

DTU users get better search results including licensed content and discounts on order fees.

Log in as DTU user

Access

Analysis