Author:
Özalp Murat,Karakuzu Cihan,Zengin Ahmet
Abstract
In this paper, distributed intrusion detection systems (IDSs)in the literature are reviewed. There are two types of IDS, depending on the interoperability. Stand-alone systems decide on their own. Distributed systems are composed of multiple components processing different data and work together to make a global decision. Distributed IDSs present some difficulties compared to stand-alone systems. For example, problems such as the structure of message communication, establishment of a trust mechanism, joint decision making are the issues discussed in the studies related to such systems. A detailed literature review has been made for the distributed IDSs which are the focus of our study. The studies considered to be within the scope of our study were investigated and presented comparatively. Although the initial studies on interoperable systems began in the 1990s, the issue is still open to improvement, as there is no widespread system that has become "product". On the other hand, due to the development of artificial intelligence systems, innovative studies are being conducted on cyber threat detection. Therefore, the subject is thought to be open to improvement and in the last part of the study, suggestions are given for those who want to work on the subject.
Reference28 articles.
1. F. Cuppens and R. Ortalo, “LAMBDA: A Language to Model a Database for Detection of Attacks,” Springer, Berlin, Heidelberg, 2000, pp. 197-216.
2. F. Cuppens and A. Miege, “Alert correlation in a cooperative intrusion detection framework,” in Proceedings 2002 IEEE Symposium on Security and Privacy, pp. 202-215.
3. S. T. Eckmann, G. Vigna, and R. A. Kemmerer, “STATL: An attack language for state-based intrusion detection,” J. Comput. Secur., vol. 10, no. 1-2, pp. 71-103, Jan. 2002.
4. H. Debar, D. Curry, and B. Feinstein, “The Intrusion Detection Message Exchange Format (IDMEF),” RFC, Mar-2007.
5. R. Danyliw, J. Meijer, and Y. Demchenko, “RFC5070 - The Incident Object Description Exchange Format,” IETF, 2007.