{"title":"Enhancing interoperability of security operation center to heterogeneous intrusion detection systems","authors":"A. C. Lin, Hsing-Kuo Wong, Tzong-Chen Wu","doi":"10.1109/CCST.2005.1594841","DOIUrl":null,"url":null,"abstract":"This study aimed at enhancing the interoperability of a SOC (security operation center) to heterogeneous IDSes (intrusion detection systems) by designing a few EDMEF (intrusion detection message exchange format) templates. The adopted approach based on the specification of IDMEF and the need of incident detection. The resulted templates have two types that are for use of most usual alerts and aggregation of similar alerts respectively. The objectives of these templates are to simplify the usage of IDMEF and to improve the disadvantages originating from un-customized IDMEF. The results support the objectives of this study.","PeriodicalId":411051,"journal":{"name":"Proceedings 39th Annual 2005 International Carnahan Conference on Security Technology","volume":"43 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings 39th Annual 2005 International Carnahan Conference on Security Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CCST.2005.1594841","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
This study aimed at enhancing the interoperability of a SOC (security operation center) to heterogeneous IDSes (intrusion detection systems) by designing a few EDMEF (intrusion detection message exchange format) templates. The adopted approach based on the specification of IDMEF and the need of incident detection. The resulted templates have two types that are for use of most usual alerts and aggregation of similar alerts respectively. The objectives of these templates are to simplify the usage of IDMEF and to improve the disadvantages originating from un-customized IDMEF. The results support the objectives of this study.