DocumentCode :
1563717
Title :
A new paradigm for intrusion detection systems
Author :
Pressley, Tony
fYear :
2002
fDate :
6/24/1905 12:00:00 AM
Firstpage :
390
Abstract :
Summary form only given. The US Army Research Laboratory through its Information Assurance Center (IAC) seeks to evolve and continuously develop an IA capability that sets the Army and DoD standard for protecting computing and communications infrastructure from unauthorized access, illicit exploitation, component damage, and denial of service to authorized users. The IAC has two components, an operational computer emergency response team that monitors a major Department of Defense research network on a 27 × 7 basis, and a research component. Unlike many similar activities, the ARL computer emergency response team employs multiple network intrusion detection system tools to accomplish its mission, and serves as a testbed for IDS tools transitioning from universities and industry into the government and commercial sectors. The IAC\´s in-house research component is focused on architecture improvements to promote data fusion across sensors and time. Issues which the new architecture address include timeliness, archiving issues, and the incorporation of both signature and anomaly IDS tools into the architecture and the fusion of the information resulting from these different approaches. The IAC has a number of collaborations with industry and academia to promote IDS tools/methodologies focused on network surveillance, intrusion detection systems focused on advanced networking (OC12 and above), and the "insider threat".
Keywords :
computer networks; emergency services; military communication; military computing; military standards; safety systems; security of data; sensor fusion; telecommunication security; telecommunication standards; ARL computer emergency response team; Army standard; Department of Defense research network; DoD standard; IAC; IDS tools; IDS tools/methodologies; Information Assurance Center; OC12; US Army Research Laboratory; advanced networking; archiving; commercial sector; communications infrastructure; component damage; computer emergency response team; computing infrastructure; data fusion; denial of service; government sector; illicit exploitation; industry; insider threat; intrusion detection systems; network intrusion detection system tools; network surveillance; sensors; testbed; timeliness; unauthorized access protection; universities; Communication standards; Computer crime; Computer displays; Computer networks; Educational institutions; Intrusion detection; Military computing; Protection; Standards development; System testing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Communications and Networks, 2002. Proceedings. Eleventh International Conference on
ISSN :
1095-2055
Print_ISBN :
0-7803-7553-X
Type :
conf
DOI :
10.1109/ICCCN.2002.1206523
Filename :
1206523
Link To Document :
بازگشت