An Effective Fault-Tolerant Intrusion Detection System under Distributed Environment

Author:

Hong Bo1ORCID,Wang Hui1ORCID,Cao Zijian1

Affiliation:

1. School of Computer Science and Engineering, Xi’an Technological University, Xi’an 710021, China

Abstract

Traditional intrusion detection system is limited to a single network or several hosts, which has been seriously unable to fulfill the growing information security problems. This paper uses the distributed technology to design and implement an intrusion detection system (IDS) based on the hybrid of Hadoop with some effective open-source technologies. On the one hand, it can efficiently realize the data acquisition and analysis under distributed environment. On the other hand, it can solve the problems of single-point fault-tolerant and the insufficient data processing capacity of the traditional intrusion detection system. In this IDS, RabbitMQ, Flume, and MongoDB are utilized to act as the middleware of this system to build the system environment which includes the collector, analyzer, and data storage. By detecting the CPU and memory usage of hosts, TCP connections, network bandwidth, web server operation logs, and the logs of user behavior, the proposed IDS especially focuses on monitoring the first four parts, which can better detect external distributed denial of service attacks and intrusions and send automatically alarm service information to the administrators.

Funder

Xi’an Technological University

Publisher

Hindawi Limited

Subject

Electrical and Electronic Engineering,Computer Networks and Communications,Information Systems

Reference23 articles.

1. Broad-scale distributed intrusion detection system;R. Z. Yang;Network and Information Security,2020

2. Cloud Data Protection for the Masses

3. Human perspective to anomaly detection for cybersecurity

4. Distributed intrusion detection based on hybrid gene expression programming and cloud computing in a cyber physical power system

5. Algorithms. Study data from Nanjing University update understanding of algorithms (distributed intrusion detection based on hybrid gene expression programming and cloud computing in a cyber physical power system);S. Deng;Journal of Engineering,2017

Cited by 3 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. A Data Intrusion Tolerance Model Based on an Improved Evolutionary Game Theory for the Energy Internet;Computers, Materials & Continua;2024

2. Advanced Machine Learning for Runtime Data Generation;12th Latin-American Symposium on Dependable and Secure Computing;2023-10-16

3. Design and Protection Strategy of Distributed Intrusion Detection System in Big Data Environment;Computational Intelligence and Neuroscience;2022-06-29

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3