Sang-Kil Park, Kiyoung Kim, Jong-Su Jang, Bongnam Noh
{"title":"Supporting interoperability to heterogeneous IDS in secure networking framework","authors":"Sang-Kil Park, Kiyoung Kim, Jong-Su Jang, Bongnam Noh","doi":"10.1109/APCC.2003.1274479","DOIUrl":null,"url":null,"abstract":"On 22 October 2002, ICANN, the Internet's main governing body, acknowledged that a massive distributed denial-of-service attack briefly shut down seven of the 13 central Domain Name Services servers that manage Internet traffic worldwide. Prompt action by DNS server operators minimized the duration and impact of the attack, which had little effect on overall Internet performance. Intrusion detection systems are researched and developed to detect attacks from outside world since 1980. Intrusion detection systems create an alert data or log data when detect an intrusion. But Many IDS uses heterogeneous data set, so these data must be mapped to another format. IDWG in IETF proposed IDMEF. This paper designs an alert data format compatible IDMEF. The secure networking framework is consisted of SGS and CPCS. SGS acts as an intrusion detection system on edge of network ingress point, and CPCS acts as a higher-level server. SGS makes an alert data compatible IDMEF and sends it to CPCS. CPCS parses an IDMEF alert data and makes an alert object for using correlation analysis. SGS can see its area only, but CPCS can see wide network area. CPCS can detect more complex attacks as well as support integrated management through cooperating each other. In the view of alert processing we converted raw alert data to Ladon-alert data to support interoperability. We use IDMEF-compatible alert datat structure. We have designed and developed integrated IDS on gateway, and security control server on higher-level class. Then this framework offers cooperative intrusion detection, policy based controlling.","PeriodicalId":277507,"journal":{"name":"9th Asia-Pacific Conference on Communications (IEEE Cat. No.03EX732)","volume":"133 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2003-09-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"9th Asia-Pacific Conference on Communications (IEEE Cat. No.03EX732)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/APCC.2003.1274479","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9
Abstract
On 22 October 2002, ICANN, the Internet's main governing body, acknowledged that a massive distributed denial-of-service attack briefly shut down seven of the 13 central Domain Name Services servers that manage Internet traffic worldwide. Prompt action by DNS server operators minimized the duration and impact of the attack, which had little effect on overall Internet performance. Intrusion detection systems are researched and developed to detect attacks from outside world since 1980. Intrusion detection systems create an alert data or log data when detect an intrusion. But Many IDS uses heterogeneous data set, so these data must be mapped to another format. IDWG in IETF proposed IDMEF. This paper designs an alert data format compatible IDMEF. The secure networking framework is consisted of SGS and CPCS. SGS acts as an intrusion detection system on edge of network ingress point, and CPCS acts as a higher-level server. SGS makes an alert data compatible IDMEF and sends it to CPCS. CPCS parses an IDMEF alert data and makes an alert object for using correlation analysis. SGS can see its area only, but CPCS can see wide network area. CPCS can detect more complex attacks as well as support integrated management through cooperating each other. In the view of alert processing we converted raw alert data to Ladon-alert data to support interoperability. We use IDMEF-compatible alert datat structure. We have designed and developed integrated IDS on gateway, and security control server on higher-level class. Then this framework offers cooperative intrusion detection, policy based controlling.