Title :
A SNMP-based platform for distributed stateful intrusion detection in enterprise networks
Author :
Gaspary, Luciano Paschoal ; Sanchez, Ricardo Nabinger ; Antunes, Diego Wentz ; Meneghetti, Edgar
Author_Institution :
Programa Interdisciplinar de Pos-Graduacao em Computacao Aplicada, Univ. do Vale do Rio dos Sinos, Sao Leopoldo, Brazil
Abstract :
In recent years, intrusion detection systems (IDSs) use has increased into detect security breaches in both systems and networks. However, widespread IDS usage has been hindered by several challenges, including: 1) time-consuming configuration and analysis; 2) integration difficulties with existing network management infrastructure; and 3) the inability to add new attack signatures in a well-understood, yet expressive high-level notation. This paper presents the ID-Trace Management Platform, an extension of the simple network management protocol infrastructure based on the Internet Engineering Task Force (IETF) script management information base (Script MIB) to support distributed stateful intrusion detection in enterprise networks. It provides mechanisms allowing a management station to delegate security-related tasks to mid-level managers (MLMs) that, in turn, interact with monitoring and action agents to execute these tasks. Protocol trace specification language specifications are used by the MLMs to program monitoring agents that sniff packets on the network comparing their signatures to those of known attack signatures. With the information gathered from the monitoring process, the MLMs may execute procedures via the action agents (Java, Tcl, or Perl scripts), enabling the automation of several security tasks (including reactive and proactive tasks). The platform also provides notification mechanisms (traps) so that MLMs can report the occurrence of major events to the management station.
Keywords :
Internet; Java; authorisation; business communication; computer network management; digital signatures; program verification; software agents; specification languages; system monitoring; telecommunication security; transport protocols; ID-trace management platform; IDS system; IETF; Internet engineering task force; MLM; SNMP-based platform; action agent; distributed stateful intrusion detection; enterprise network; known attack signature; mid-level manager; notification mechanism; program monitoring agent; protocol trace specification language; script MIB; script management information base; simple network management protocol; site security monitoring; sniff packet; time-consuming configuration; Automation; Computerized monitoring; Engineering management; IP networks; Information management; Information security; Intrusion detection; Java; Protocols; Specification languages; Computer network management; computer network security; site security monitoring;
Journal_Title :
Selected Areas in Communications, IEEE Journal on
DOI :
10.1109/JSAC.2005.854116