Policy-Controlled Event Management for Distributed Intrusion Detection

  • Authors:
  • Christian Kreibich;Robin Sommer

  • Affiliations:
  • University of Cambridge;Technische Universität München

  • Venue:
  • ICDCSW '05 Proceedings of the Fourth International Workshop on Distributed Event-Based Systems (DEBS) (ICDCSW'05) - Volume 04
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

A powerful strategy in intrusion detection is the separation of surveillance mechanisms from a siteýs policy for processing observed events. The Bro intrusion detection system has been using the notion of policy-neutral events as the basic building blocks for the formulation of a siteýs security policy since its conception. A recent addition to the system is the ability to exchange events with other Bro peers to allow distributed detection. In this paper we extend Broýs existing event model to fulfill the requirements of scalable policy-controlled distributed event management, including mechanisms for event publication, subscription, processing, propagation, and correlation.