在安全的网络框架中支持异构IDS的互操作性

Sang-Kil Park, Kiyoung Kim, Jong-Su Jang, Bongnam Noh
{"title":"在安全的网络框架中支持异构IDS的互操作性","authors":"Sang-Kil Park, Kiyoung Kim, Jong-Su Jang, Bongnam Noh","doi":"10.1109/APCC.2003.1274479","DOIUrl":null,"url":null,"abstract":"On 22 October 2002, ICANN, the Internet's main governing body, acknowledged that a massive distributed denial-of-service attack briefly shut down seven of the 13 central Domain Name Services servers that manage Internet traffic worldwide. Prompt action by DNS server operators minimized the duration and impact of the attack, which had little effect on overall Internet performance. Intrusion detection systems are researched and developed to detect attacks from outside world since 1980. Intrusion detection systems create an alert data or log data when detect an intrusion. But Many IDS uses heterogeneous data set, so these data must be mapped to another format. IDWG in IETF proposed IDMEF. This paper designs an alert data format compatible IDMEF. The secure networking framework is consisted of SGS and CPCS. SGS acts as an intrusion detection system on edge of network ingress point, and CPCS acts as a higher-level server. SGS makes an alert data compatible IDMEF and sends it to CPCS. CPCS parses an IDMEF alert data and makes an alert object for using correlation analysis. SGS can see its area only, but CPCS can see wide network area. CPCS can detect more complex attacks as well as support integrated management through cooperating each other. In the view of alert processing we converted raw alert data to Ladon-alert data to support interoperability. We use IDMEF-compatible alert datat structure. We have designed and developed integrated IDS on gateway, and security control server on higher-level class. Then this framework offers cooperative intrusion detection, policy based controlling.","PeriodicalId":277507,"journal":{"name":"9th Asia-Pacific Conference on Communications (IEEE Cat. No.03EX732)","volume":"133 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2003-09-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":"{\"title\":\"Supporting interoperability to heterogeneous IDS in secure networking framework\",\"authors\":\"Sang-Kil Park, Kiyoung Kim, Jong-Su Jang, Bongnam Noh\",\"doi\":\"10.1109/APCC.2003.1274479\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"On 22 October 2002, ICANN, the Internet's main governing body, acknowledged that a massive distributed denial-of-service attack briefly shut down seven of the 13 central Domain Name Services servers that manage Internet traffic worldwide. Prompt action by DNS server operators minimized the duration and impact of the attack, which had little effect on overall Internet performance. Intrusion detection systems are researched and developed to detect attacks from outside world since 1980. Intrusion detection systems create an alert data or log data when detect an intrusion. But Many IDS uses heterogeneous data set, so these data must be mapped to another format. IDWG in IETF proposed IDMEF. This paper designs an alert data format compatible IDMEF. The secure networking framework is consisted of SGS and CPCS. SGS acts as an intrusion detection system on edge of network ingress point, and CPCS acts as a higher-level server. SGS makes an alert data compatible IDMEF and sends it to CPCS. CPCS parses an IDMEF alert data and makes an alert object for using correlation analysis. SGS can see its area only, but CPCS can see wide network area. CPCS can detect more complex attacks as well as support integrated management through cooperating each other. In the view of alert processing we converted raw alert data to Ladon-alert data to support interoperability. We use IDMEF-compatible alert datat structure. We have designed and developed integrated IDS on gateway, and security control server on higher-level class. Then this framework offers cooperative intrusion detection, policy based controlling.\",\"PeriodicalId\":277507,\"journal\":{\"name\":\"9th Asia-Pacific Conference on Communications (IEEE Cat. No.03EX732)\",\"volume\":\"133 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2003-09-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"9\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"9th Asia-Pacific Conference on Communications (IEEE Cat. No.03EX732)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/APCC.2003.1274479\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"9th Asia-Pacific Conference on Communications (IEEE Cat. No.03EX732)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/APCC.2003.1274479","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

摘要

2002年10月22日,互联网的主要管理机构ICANN承认,一次大规模的分布式拒绝服务攻击使管理全球互联网流量的13个中央域名服务服务器中的7个短暂关闭。DNS服务器运营商迅速采取行动,最大限度地减少了攻击的持续时间和影响,对整体互联网性能影响不大。入侵检测系统是从1980年开始研究和发展的,目的是检测来自外部世界的攻击。当检测到入侵时,入侵检测系统会创建警报数据或日志数据。但是许多IDS使用异构数据集,因此必须将这些数据映射为另一种格式。IETF中的IDWG提出了IDMEF。本文设计了一种兼容IDMEF的警报数据格式。安全组网框架由SGS和CPCS组成。SGS作为网络入口点边缘的入侵检测系统,CPCS作为更高级的服务器。SGS制作警报数据兼容IDMEF并发送给CPCS。CPCS解析IDMEF警报数据并生成警报对象,以便进行相关性分析。SGS只能看到它的区域,而CPCS可以看到广泛的网络区域。CPCS可以通过相互协作检测更复杂的攻击,并支持集成管理。在警报处理方面,我们将原始警报数据转换为ladon -警报数据,以支持互操作性。我们使用与idmef兼容的警报数据结构。在网关上设计开发了集成的IDS,在更高层上设计开发了安全控制服务器。然后,该框架提供了协同入侵检测和基于策略的控制。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Supporting interoperability to heterogeneous IDS in secure networking framework
On 22 October 2002, ICANN, the Internet's main governing body, acknowledged that a massive distributed denial-of-service attack briefly shut down seven of the 13 central Domain Name Services servers that manage Internet traffic worldwide. Prompt action by DNS server operators minimized the duration and impact of the attack, which had little effect on overall Internet performance. Intrusion detection systems are researched and developed to detect attacks from outside world since 1980. Intrusion detection systems create an alert data or log data when detect an intrusion. But Many IDS uses heterogeneous data set, so these data must be mapped to another format. IDWG in IETF proposed IDMEF. This paper designs an alert data format compatible IDMEF. The secure networking framework is consisted of SGS and CPCS. SGS acts as an intrusion detection system on edge of network ingress point, and CPCS acts as a higher-level server. SGS makes an alert data compatible IDMEF and sends it to CPCS. CPCS parses an IDMEF alert data and makes an alert object for using correlation analysis. SGS can see its area only, but CPCS can see wide network area. CPCS can detect more complex attacks as well as support integrated management through cooperating each other. In the view of alert processing we converted raw alert data to Ladon-alert data to support interoperability. We use IDMEF-compatible alert datat structure. We have designed and developed integrated IDS on gateway, and security control server on higher-level class. Then this framework offers cooperative intrusion detection, policy based controlling.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信