Network Events Correlation for Federated Networks Protection System

Brzostek, J

  • Towards a Service-Based Internet - 4th European Conference;
  • Tom: 6994;
  • Strony: 100-111;
  • 2011;

In this paper a concept and an architecture of the Federated Networks Protection System (FNPS) is proposed. The system components are described and, particularly, the Decision Module (FNPS-DM) is discussed. The major contributions of the paper are: concept of federated networks security, the proposition of the network events correlation approach and semantic notations aimed at detecting complex cyber attacks and 0-day exploits. Moreover P2P based communication between federated networks is proposed.