Log-based distributed intrusion detection for hybrid networks

Françoise Sailhan, Julien Bourgeois · 2008

We propose a novel hybrid distributed security operation center which collects logs that are generated by any application, service, and protocol regardless of the layer of the protocol stack and the device (e.g., router); providing a global view of the supervised system based on which complex and distributed intrusions can be detected. Our HDSOC further (i) distributes its capabilities and (ii) provides extensive coordination capabilities for guarantying that both the network and the HDSOC components do not constitute isolated entities largely unaware of each others.

Read the paper · More papers on PaperTik