A Case for Network-wide Orchestration of Host-based Intrusion Detection and Response

๐Ÿ“… 2025-04-08
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
Existing host-based intrusion detection systems (IDS) suffer from isolated alerts and delayed responses, failing to meet the requirements of zero-trust architectures and real-time collaborative defense. To address these limitations, this paper proposes the first network-level dynamic orchestration paradigm supporting zero-restart extensibility. Our approach centers on a centralized orchestrator that enables lightweight, programmable detection logic on hosts via eBPFโ€”allowing remote, hot updates without service interruption. We further design a centralized policy distribution mechanism and a real-time streaming alert aggregation engine to facilitate cross-host attack correlation and coordinated response. Evaluated on two realistic attack scenarios, our prototype achieves 100% interception rate with an average response latency under 800 ms. This significantly overcomes the inherent limitations of standalone detection, establishing a novel, resilient intrusion defense paradigm tailored for zero-trust environments.

Technology Category

Search and Optimization: Distributed SearchMultiagent Systems: Coordination and CollaborationMachine Learning: Hardware-aware ML

Application Category

Systems and Infrastructure for Web, Mobile and WoT: Decentralized Web and Fediverse systemsEconomics, Online Markets and Human Computation: Incentives in network design for Web infrastructures and ecosystemsGraph Algorithms and Modeling for the Web: Efficient manipulation of static and dynamic Web-related graphs
๐Ÿ“ Abstract
Recent cyber incidents and the push for zero trust security underscore the necessity of monitoring host-level events. However, current host-level intrusion detection systems (IDS) lack the ability to correlate alerts and coordinate a network-wide response in real time. Motivated by advances in system-level extensions free of rebooting and network-wide orchestration of host actions, we propose using a central IDS orchestrator to remotely program the logic of each host IDS and collect the alerts generated in real time. In this paper, we make arguments for such a system concept and provide a high level design of the main system components. Furthermore, we have developed a system prototype and evaluated it using two experimental scenarios rooted from real-world attacks. The evaluation results show that the host-based IDS orchestration system is able to defend against the attacks effectively.
Problem

Research questions and friction points this paper is trying to address.

Lack of real-time network-wide alert correlation in host IDS
Need for centralized orchestration of host intrusion detection
Enhancing defense against attacks via coordinated host IDS responses
Innovation

Methods, ideas, or system contributions that make the work stand out.

Central IDS orchestrator for real-time alerts
Remote programming of host IDS logic
Network-wide defense against real-world attacks
๐Ÿ”Ž Similar Papers
No similar papers found.
๐Ÿ’ผ Related Jobs
No related jobs found.