Intrusion detection in distributed systems using fingerprinting and massive event correlation
Florian Skopik, Roman Fiedler · 2013
Abstract: New computing paradigms, such as mobile computing and cloud com-puting introduce considerable vulnerabilities to today’s society. Systems do not only become more and more connected and interdependent, but multi-billion dollar mar-kets have led to the emergence of new – economically motivated – forms of crime. Additionally, since most of today’s critical infrastructures are controlled by complex ICT systems, service outages due to attacks can cause serious situations. However, because of the increasing scale and complexity of today’s networked infrastructures, traditional protection mechanisms, such as firewalls and anti-virus software seem to become insufficient to guarantee an adequate level of security. In this paper, we present a novel intrusion detection concept which utilizes distributed monitoring and massive data correlation techniques to discover potential attack traces. This is crucial to es-tablish situational awareness on a higher level and finally make informed decisions on mitigation strategies. In contrast to many others, this approach operates not on the net-work layer, but uses semantically rich service logs. We demonstrate the feasibility of our fingerprint-based anomaly detection approach in context of a real-world use cases and discuss its applicability. 1