An Efficient and Scalable Coordinating Algorithm for Distributed Network Intrusion DeComputer network, in particular, Internet, becomes a vital
part of human society and economy. Network services such
as social networks and web sites are integrated seamlessly
into people’s daily life. On the other hand, e-commerce has
rapidly replaced brick and mortar businesses. However, this
advancement also brings threat as well. Network attacks such
as spoofing, wiretapping or denial-of-service have posed serious
threat on computer operations and also human users.
To detect denial-of-service attack, intrusion detection systems
are generally deployed. However, when a network is large,
multiple detectors need to be deployed in many parts of the
network. Distributed intrusion detection system is more viable,
in terms of traffic overhead and bottle neck problem, than
centralized approach. This paper proposes a tree-based coordinating
algorithm for distributed network intrusion system. In
this approach, each detector observes local network activity,
then reports its activity to its parent and children. Based
on aggregated information from local, parent’s and children’s
activity, each detector makes a decision whether to report
an attack. Section II gives an overview on background and
related work. Detail description of the proposed algorithm is
in Section III. Experimental results are shown in Section IV.
Finally, a conclusion is given in Section V.tection System