A Service Based Approach to a New Generation of Intrusion Detection Systems

A. Bosin, N. Dessì, B. Pes
{"title":"A Service Based Approach to a New Generation of Intrusion Detection Systems","authors":"A. Bosin, N. Dessì, B. Pes","doi":"10.1109/ECOWS.2008.16","DOIUrl":null,"url":null,"abstract":"Intrusion detection systems (IDSs) aim at detecting malicious or unauthorized activities targeting a network and its resources. Usually engineered as self-contained applications, current IDSs are limited in protecting collaborative computing environments, like grids, whose security amplifies the concerns about intrusions and motivates advanced organizing paradigms and technical solutions for effective attack detection. We envision a new generation of IDSs defined by a set of services supporting security managers in improving the overall network security. Specifically, we show how to model the ID processes as a set of plans that a security manager may go through on a network of cooperative nodes interacting with one another in order to offer or to ask for services. Services correspond to specialized ID tasks and encapsulate problem solving and simulation capabilities. Complex ID activities are expressed by workflows, the focus being on flexibility, reuse and interoperability of ID services. Some implementation hints are suggested.","PeriodicalId":227761,"journal":{"name":"2008 Sixth European Conference on Web Services","volume":"21 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-11-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 Sixth European Conference on Web Services","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ECOWS.2008.16","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Intrusion detection systems (IDSs) aim at detecting malicious or unauthorized activities targeting a network and its resources. Usually engineered as self-contained applications, current IDSs are limited in protecting collaborative computing environments, like grids, whose security amplifies the concerns about intrusions and motivates advanced organizing paradigms and technical solutions for effective attack detection. We envision a new generation of IDSs defined by a set of services supporting security managers in improving the overall network security. Specifically, we show how to model the ID processes as a set of plans that a security manager may go through on a network of cooperative nodes interacting with one another in order to offer or to ask for services. Services correspond to specialized ID tasks and encapsulate problem solving and simulation capabilities. Complex ID activities are expressed by workflows, the focus being on flexibility, reuse and interoperability of ID services. Some implementation hints are suggested.
基于服务的新一代入侵检测系统
入侵检测系统(ids)旨在检测针对网络及其资源的恶意或未经授权的活动。通常作为自包含的应用程序设计,当前的ids在保护协作计算环境(如网格)方面受到限制,其安全性放大了对入侵的关注,并激发了用于有效攻击检测的高级组织范例和技术解决方案。我们设想新一代的入侵防御系统由一组支持安全管理人员提高整体网络安全性的服务定义。具体来说,我们将展示如何将ID过程建模为一组计划,安全管理器可能会在相互交互的协作节点网络上经过这些计划,以便提供或请求服务。服务对应于专门的ID任务,并封装了解决问题和模拟功能。复杂的ID活动由工作流表示,重点是ID服务的灵活性、重用性和互操作性。给出了一些实现提示。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信