Supporting interoperability to heterogeneous IDS in secure networking framework

被引:0
作者
Park, SK [1 ]
Kim, KY [1 ]
Jang, JS [1 ]
Noh, BN [1 ]
机构
[1] Elect & Telecommun Res Inst, Informat Secur Res Div, Taejon 305350, South Korea
来源
APCC 2003: 9TH ASIA-PACIFIC CONFERENCE ON COMMUNICATION, VOLS 1-3, PROCEEDINGS | 2003年
关键词
IDS interoperability; IDS; PBNM;
D O I
10.1109/APCC.2003.1274479
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
On 22 October 2002, ICANN, the Internet's main governing body, acknowledged that a massive distributed denial-of-service attack briefly shut down seven of the 13 central Domain Name Services servers that manage Internet traffic worldwide. Prompt action by DNS server operators minimized the duration and impact of the attack, which had little effect on overall Internet performance. Intrusion Detection Systems are researched and developed to detect attacks from outside world since 1980. Intrusion Detection Systems create an alert data or log data when detect an intrusion. But Many IDS uses heterogeneous Data set, so these data must be mapped to another format. IDWG in IETF proposed IDMEF. This paper designs an alert data format compatible IDMEF. The secure networking framework is consisted of SGS and CPCS. SGS acts as an intrusion detection system on edge of network ingress point, and CPCS acts as a higher-level server. SGS makes an alert data compatible IDMEF and sends it to CPCS. CPCS parses an IDMEF alert data and makes an alert object for using correlation analysis. SGS can see its area only, but CPCS can see wide network area. CPCS can detect more complex attacks as well as support integrated management through cooperating each other. In the view of alert processing we converted raw alert data to Ladon-alert data to support interoperability. We use IDMEF-compatible alert datat structure. We-have desined and developed integrated IDS on gateway, and security control server on higher-level class. Then this framework offers cooperative intrusion detection, policy based controlling.
引用
收藏
页码:844 / 848
页数:5
相关论文
共 11 条
[1]  
AMOROSO EG, 1999, INTRUSION DETECTION
[2]  
ANDERSON D, 1995, SRICLS9507
[3]  
BALASUBRAMANIYA.JS, 1998, 9805 COAST
[4]  
Curry D., 2002, INTRUSION DETECTION
[5]  
Denning D. E., 1986, Proceedings of the 1986 IEEE Symposium on Security and Privacy (Cat. No.86CH2292-1), P118
[6]  
GREEN J, 1999, P WORKSH INTR DET NE
[7]  
Javitz H. S., 1991, Proceedings. 1991 IEEE Computer Society Symposium on Research in Security and Privacy (Cat. No.91CH2986-8), P316, DOI 10.1109/RISP.1991.130799
[8]  
Kahn C., 1998, COMMON INTRUSION DET
[9]  
PARK SK, 2002, P APNOMS2002 SEPT
[10]  
PARK SK, 2002, J KICS