Decoupling Components of an Attack Prevention System using Publish/Subscribe
Citation key GarciaEtAl:2005:DecouplingAPSPubSub
Author Joaquín García and Michael A. Jaeger and Gero Mühl and Joan Borrell
Title of Book Proceedings of the 2005 IFIP conference on Intelligence in Communication Systems (INTELLCOMM2005)
Pages 87–97
Year 2005
ISBN 978-0-387-29121-5
ISSN 1571-5736
DOI 10.1007/0-387-32015-6_9
Address Montréal, Canada
Volume 190
Month oct
Publisher Springer
Series IFIP International Federation for Information Processing
Organization IFIP
Abstract Distributed and coordinated attacks can disrupt electronic commerce applications and cause large revenue losses. The prevention of these attacks is not possible by just considering information from isolated sources of the network. A global view of the whole system is necessary to react against the different actions of such an attack. We are currently working on a decentralized attack prevention framework that is targeted at detecting as well as reacting to these attacks. The cooperation between the different entities of this system has been efficiently solved through the use of a publish/subscribe model. In this paper we first present the advantages and convenience in using this communication paradigm for a general decentralized attack prevention framework. Then, we present the design for our specific approach. Finally, we shortly discuss our implementation based on a freely available publish/subscribe message oriented middleware.
