Assessing the Uncertainty of Communication Patterns in Distributed Intrusion Detection System

A paper proposes a formal framework for communication patterns’ uncertainty assessment within a distributed multiagent IDS architecture. The role of the detection of communication anomalies in IDS is discussed then it is shown how sequences of detectable patterns like fan-in, fan-out values for given network node and clustering coefficients can be used to detect network anomalies caused by security incidents (worm attack, virus spreading). It is defined how to use the proposed techniques in distributed IDS and backtrack the incidents.