A Collaborative Event Processing System for Protection of Critical Infrastructures from Cyber Attacks


We describe an Internet-based collaborative environment that protects geographically dispersed organizations of a critical infrastructure (e.g., financial institutions, telco providers) from coordinated cyber attacks. A specific instance of a collaborative environment for detecting malicious inter-domain port scans is introduced. This instance uses the open source Complex Event Processing (CEP) engine ESPER to correlate massive amounts of network traffic data exhibiting the evidence of those scans. The paper presents two inter-domain SYN port scan detection algorithms we designed, implemented in ESPER, and deployed on the collaborative environment; namely, Rank-based SYN (R-SYN) and Line Fitting. The paper shows the usefulness of the collaboration in terms of detection accuracy. Finally, it shows how Line Fitting can both achieve a higher detection accuracy with a smaller number of participants than R-SYN, and exhibit better detection latencies than R-SYN in the presence of low link bandwidths (i.e., less than 3Mbit/s) connecting the organizations to Esper.

DOI: 10.1007/978-3-642-24270-0_23

Extracted Key Phrases

5 Figures and Tables

Showing 1-10 of 24 references

Communication Middleware for Monitoring Financial Critical Infrastructures

  • 2011

WANem The Wide Area Network emulator

  • 2011

Advisory: Weak PNG in PHP session ID generation leads to session hijacking

  • Andreas Bogk
  • 2010

JBoss Drools Fusion. http://www.jboss.org/drools/drools-fusion.html

  • 2010

Snort: an open source network intrusion prevention and detection system (IDS/IPS)

  • 2010

the Crossfire: Critical Infrastructure in the Age of Cyber War

  • S Baker, S Waterman
  • 2010