Implementing the Intrusion Detection Exchange Protocol

  • Authors:
  • T. Buchheim;M. Erlinger;B. Feinstein;G. Matthews;R. Pollock;J. Betser;A. Walther

  • Affiliations:
  • -;-;-;-;-;-;-

  • Venue:
  • ACSAC '01 Proceedings of the 17th Annual Computer Security Applications Conference
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

We describe the goals of the IETF's Intrusion Detection Working Group (IDWG) and the requirements for a transportprotocol to communicate among intrusion detection systems. We then describe the design and implementation ofIAP, the first attempt at such a protocol. After a discussion of IAP's limitations, we discuss BEEP, a new IETF generalframework for application protocols. We then describe the Intrusion Detection Exchange Protocol (IDXP), a transportprotocol designed and implemented within the BEEP framework that fulfills the IDWG requirements for its transportprotocol. We conclude by discussing probable future directions for this ongoing effort.