Enhancing Challenge-based Collaborative Intrusion Detection against Insider Attacks using Spatial Correlation

Wenjuan Li, Weizhi Meng, Javier Parra-Arnau, Kim Kwang Raymond Choo

Research output: Chapter in book / Conference proceedingConference article published in proceeding or bookAcademic researchpeer-review

9 Citations (Scopus)

Abstract

With cyber-attacks becoming more complicated and the networks increasingly interconnected, there has been a move towards using collaborative intrusion detection networks (CIDNs) to identify cyber-threats more effectively. However, insider attacks may remain challenging to mitigate in CIDNs, as the intruders are able to control one or more internal nodes. Challenge- based trust mechanism is one promising solution to help safeguard CIDNs against common insider attacks, but not necessarily against advanced attacks such as passive message fingerprint attacks. In this work, we focus on challenge-based trust mechanism and advocate that considering additional level of trust can enhance the robustness of CIDNs. Specifically, we design an enhanced trust management scheme by checking spatial correlation among nodes' behavior, regarding forwarding delay, packet dropping and sending rate. Then, we evaluate our approach in a simulated environment, as well as a realworld environment in collaboration with an IT organization. Experimental results demonstrate that our approach can help enhance the robustness of challenge-based trust mechanism by detecting malicious nodes faster than similar approaches (i.e., reducing time consumption by two to three days).

Original languageEnglish
Title of host publication2021 IEEE Conference on Dependable and Secure Computing, DSC 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781728175348
DOIs
Publication statusPublished - 30 Jan 2021
Externally publishedYes
Event2021 IEEE Conference on Dependable and Secure Computing, DSC 2021 - Aizuwakamatsu, Fukushima, Japan
Duration: 30 Jan 20212 Feb 2021

Publication series

Name2021 IEEE Conference on Dependable and Secure Computing, DSC 2021

Conference

Conference2021 IEEE Conference on Dependable and Secure Computing, DSC 2021
Country/TerritoryJapan
CityAizuwakamatsu, Fukushima
Period30/01/212/02/21

Keywords

  • Advanced Insider Threat
  • Challenge-based Trust Management
  • Collaborative Intrusion Detection
  • Spatial Correlation
  • Trust Computation

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Information Systems and Management
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'Enhancing Challenge-based Collaborative Intrusion Detection against Insider Attacks using Spatial Correlation'. Together they form a unique fingerprint.

Cite this