DocumentCode :
1178802
Title :
Hi-DRA: Intrusion Detection for Internet Security
Author :
Kemmerer, Richard A. ; Vigna, Giovanni
Author_Institution :
Reliable Software Group, California Univ., Santa Barbara, CA, USA
Volume :
93
Issue :
10
fYear :
2005
Firstpage :
1848
Lastpage :
1857
Abstract :
Intrusion detection systems monitor computer networks looking for evidence of malicious actions. Networks are complex systems, and a comprehensive intrusion detection solution has to be able to manage event streams with different content,speed, level of abstraction, and accessibility. Therefore, it is necessary to distribute intrusion detection sensors across multiple protected networks, manage their configuration as the security posture of the networks changes, and process the results of their analysis so that a high-level picture of the security state of the network can be provided to the administrators. This paper presents Hi-DRA, a network surveillance, analysis, and response system for high-speed WANs. The system provides a framework for the modular development of intrusion detection sensors in heterogeneous, high-speed environments. In addition, the system provides an infrastructure that supports the dynamic configuration of the sensors and the collection and interpretation of their results. The system, as a whole,is able to provide fine-grained monitoring across WANs and, at the same time,is able to correlate the results of the analysis of the different sensors into a high-level expressive description of security violations.
Keywords :
authorisation; telecommunication security; wide area networks; Hi-DRA; Internet security; alert correlation; anomaly detection; computer networks; computer security; heterogeneous/high-speed environments; high-speed wide area networks; intrusion detection; misuse detection; multiple protected networks; network analysis; network response system; network security; network surveillance; Computer network management; Computerized monitoring; Content management; Internet; Intrusion detection; Protection; Security; Sensor phenomena and characterization; Sensor systems; Surveillance; Alert correlation; anomaly detection; computer security; intrusion detection; misuse detection; network security; security;
fLanguage :
English
Journal_Title :
Proceedings of the IEEE
Publisher :
ieee
ISSN :
0018-9219
Type :
jour
DOI :
10.1109/JPROC.2005.853547
Filename :
1512502
Link To Document :
بازگشت