首页> 外文会议>International conference on information and knowledge engineering >Supporting Interoperability to Multi Intrusion Detection System in Secure Networking Framework
【24h】

Supporting Interoperability to Multi Intrusion Detection System in Secure Networking Framework

机译:在安全网络框架中支持多入侵检测系统的互操作性

获取原文

摘要

As intrusion and attacks which using the internet become more and more widespread and sophisticated. IDS usually detect intrusions, but these IDS on single host can detect simple attacks using audit trail. With the expansion using of Internet, IDS Developers have been focused on distributed intrusions (attacks) in Large Scale Network Environments. But, it is not easy to detect various types of intrusions, since early developed IDSs analyze audit trails generated by host operating systems, and monitoring just a single host. Therefore, we have made an effort to design and implement IDS which can detect more complex attacks as well as support integrated management through cooperating each other. In the View of Alert Processing we converted raw alert data to Ladon-alert data to support interoperability. We Use IDMEF-compatible Alert Datat Structure. We have worked on developing an integrated IDS on gateway, and Security Control Server on Higher-level class. Then this framework offer cooperative Intrusion Detection, Policy based controlling.
机译:作为利用互联网的入侵和攻击变得越来越普遍和复杂。 ID通常检测入侵,但单个主机上的这些ID可以使用审计跟踪来检测简单的攻击。随着互联网的扩展,IDS开发人员已经专注于大规模网络环境中的分布式入侵(攻击)。但是,检测各种类型的入侵并不容易,因为早期开发的IDS分析由主机操作系统生成的审计跟踪,并仅监视单个主机。因此,我们努力设计和实施可以检测更复杂的攻击的ID,并通过彼此合作来支持集成管理。在警报处理的视图中,我们将原始警报数据转换为Ladon-Alert数据以支持互操作性。我们使用IDMEF兼容的警报数据结构。我们已经在高级类上开​​发了网关上的集成ID和安全控制服务器。然后本框架提供合作入侵检测,基于策略的控制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号