Modeling requests among cooperating intrusion detection systems

  • Authors:
  • P Ning;X.S Wang;S Jajodia

  • Affiliations:
  • Center for Secure Information Systems, George Mason University, Fairfax, VA, 22030-4444, USA;Center for Secure Information Systems, George Mason University, Fairfax, VA, 22030-4444, USA;Center for Secure Information Systems, George Mason University, Fairfax, VA, 22030-4444, USA

  • Venue:
  • Computer Communications
  • Year:
  • 2000

Quantified Score

Hi-index 0.24

Visualization

Abstract

It is important for intrusion detection systems (IDSs) to share information in order to discover attacks involving multiple sites. However, no framework exists for an IDS to request from and send to another IDS data relevant to specific events. The lack of such a framework may result in a waste of processing time, storage capacity and network bandwidth. This paper proposes a formal framework modeling requests among the cooperating IDSs. To show wide applicability, the paper explores the use of the formal approach in the Common Intrusion Detection Framework (CIDF), extending CIDF components to include a query facility.