Security Portal: Computers, Information & Communication Technology

Home

 

Products & Solutions

 

Services

 

Resources

 

Links

 

Security blog

 

About us

 

What's new?
  Live data feeds

Paper “Security Risk Management for Critical Infrastructures” presented on ItAIS 2011 conference at Rome, Italy


I have been honored with the designation of ACM Senior Member (Year of Award 2010)


About Dragan Pleskonjic

Security blog >>

Books published >>

Teaching courses >>

Publications and papers >>

Projects >>


Citation and quotes at:


Book: Sigurnost računarskih sistema i mreža (Engl. Computer Systems and Networks Security)


IEEE paper: Reduction of False Positive Intrusions by Using Neural Nets


ComSIS paper: “Security of Computer Systems and Networks” Book Preview


GTECH Completes Acquisition of Sports-Betting Solutions Provider Finsoft Limited


Network Security course - VIŠER, Belgrade, Serbia (in Serbian language)


19th Annual Computer Security Applications Conference: Wireless Intrusion Detection Systems (WIDS)


IEEE paper: A development environment for generating System for Universal Network Connecting


Today's date:

 

Search this Web site:


 


Wireless Intrusion Detection System (WIDS) Products

Other Products:

WIDS Agent

WIDS Sensor

WIDS Server

WIDS Console & Management, Reporting Tools

  • WIPS - Wireless Intrusion Prevention System

  • MIDS - Mobile Intrusion Detection System

  • MIPS - Mobile Intrusion Prevention System

 

This site presents current research (and not available products) related to new approach to intrusion detection and intrusion protection systems (IDS / IPS).

This research has been particularly oriented to usage artificial intelligence, fuzzy logic and neural networks to make these systems better, easier for use and more efficient.  At 19th Annual Computer Security Applications Conference ACSAC  (December 8-12, 2003, Las Vegas, Nevada, USA) I talked about Wireless Intrusion Detection System (WIDS) and proposed multilevel and multidimensional system with components: agent, sensor, server and management and reporting tools. Also I talked at some other conferences and published couple of papers on this topic. There are different approaches to intrusion detection and prevention, but very common for commercially available IDS/IPS is that they suffer many false alarms (positive and negative) and problems with performances. Separate problem are so called “zero-day” attacks that pass majority of today’s IDS / IPS systems unnoticed.

Wireless Intrusion Detection and Prevention System, in architecture that I proposed many years ago, consist of:

  • Agent. It is software installed on mobile computer or device. It detects intrusions and attacks by analyzing traffic and behavior, making conclusions and denies it. It protects computer or computerized device. Agent works in contribution with WIDS / WIPS Sensor and Server if those are available in network and can be reached. Position of application is on personal computer including mobile devices.

  • Sensor. It is an appliance which sits in wireless network environment. It has embedded logic for detecting intrusions and alerting stations and servers about it. It alerts network users and/or administrators too. Sensor works in contribution with WIDS Agent and Server if it is available in same network. Position of application is area of wireless computer network.

  • Server. It is corporate software which integrates functions of previous two components and has additional mechanisms such as: collecting, analyzing, making conclusions (based on neural networks and fuzzy logic implementation), and giving support to WIDS Agent and Sensor. It can communicate with CERT centers and similar. It is responsible for contribution with other security software or devices (antivirus software firewalls…) Server collects information about WLAN security, events, incidents, and performance from the WIDS Sensors deployed throughout a WLAN. The server delivers the information to the WIDS Console in format that helps Network Administrators immediately identify problems. Position of application is in corporate network or remote for more mutually linked networks.

  • Console & Management, Reporting Tools. This is set of utilities intended to provide possibility of monitoring, management, tuning, and preparing various reports about WIDS / WIPS components activity. They are installed on Server, but could collect and show data from various components of WIDS / WIPS system. Single utilities could reside on Agent and Sensor devices and hey provide remote access and configuration capability too.

This is just brief description. If you are interested in more details or want to consider contribution or investment into this research and development send me e-mail.

 

WIDS - Components and System - example

 

WIDPS - Relation to other tools


Copyright © 2001-2012 Dragan Pleskonjic - All rights reserved.

Last updated: October 31, 2012