๐ค AI Summary
Existing host-based intrusion detection systems (IDS) suffer from isolated alerts and delayed responses, failing to meet the requirements of zero-trust architectures and real-time collaborative defense. To address these limitations, this paper proposes the first network-level dynamic orchestration paradigm supporting zero-restart extensibility. Our approach centers on a centralized orchestrator that enables lightweight, programmable detection logic on hosts via eBPFโallowing remote, hot updates without service interruption. We further design a centralized policy distribution mechanism and a real-time streaming alert aggregation engine to facilitate cross-host attack correlation and coordinated response. Evaluated on two realistic attack scenarios, our prototype achieves 100% interception rate with an average response latency under 800 ms. This significantly overcomes the inherent limitations of standalone detection, establishing a novel, resilient intrusion defense paradigm tailored for zero-trust environments.
๐ Abstract
Recent cyber incidents and the push for zero trust security underscore the necessity of monitoring host-level events. However, current host-level intrusion detection systems (IDS) lack the ability to correlate alerts and coordinate a network-wide response in real time. Motivated by advances in system-level extensions free of rebooting and network-wide orchestration of host actions, we propose using a central IDS orchestrator to remotely program the logic of each host IDS and collect the alerts generated in real time. In this paper, we make arguments for such a system concept and provide a high level design of the main system components. Furthermore, we have developed a system prototype and evaluated it using two experimental scenarios rooted from real-world attacks. The evaluation results show that the host-based IDS orchestration system is able to defend against the attacks effectively.