Font Size: a A A

A lightweight intrusion detection system for the cluster environment

Posted on:2004-06-07Degree:M.SType:Thesis
University:Mississippi State UniversityCandidate:Liu, ZhenFull Text:PDF
GTID:2468390011474782Subject:Computer Science
Abstract/Summary:
As clusters of Linux workstations have gained in popularity, security in this environment has become increasingly important. While prevention methods such as access control can enhance the security level of a cluster system, intrusions are still possible and therefore intrusion detection and recovery methods are necessary. In this thesis, a system architecture for an intrusion detection system in a cluster environment is presented. A prototype system called pShield based on this architecture for a Linux cluster environment is described and its capability to detect unique attacks on MPI programs is demonstrated.; The pShield system was implemented as a loadable kernel module that uses a neural network classifier to model normal behavior of processes. A new method for generating artificial anomalous data is described that uses a limited amount of attack data in training the neural network. Experimental results demonstrate that using this method rather than randomly generated anomalies reduces the false positive rate without compromising the ability to detect novel attacks. (Abstract shortened by UMI.)...
Keywords/Search Tags:Cluster, Intrusion detection, System, Environment
Related items