Combining multiple intrusion detection and response technologies in an active networking based architecture
Zusammenfassung
With the ever growing number of hosts connected to the Internet, representing potential sources of malicious attacks, and increasing sophistication of attacking techniques and automated attacking tools, network intrusion detection and response has evolved into a very active field of research in recent years and a wide variety of approaches has been developed [LFG+00, NN01]. However, isolated operation of specific intrusion detection and defense technologies generally exhibits only the specific strengths and drawbacks of one particular approach. In order to allow for a co-ordinated combination of existing and emerging security technologies (e.g. signature based detection, anomaly detection, DDoS response mechanisms, honeypots, etc.) we propose a flexible intrusion detection and response framework called FIDRAN [HJS03] that is based on active networking technology. Principal findings so far are that active networking proves to be a well suited technology for intrusion detection and response, that the load of intrusion detection can be distributed among multiple systems with this approach, and that the overhead stays in acceptable ranges.
- Vollständige Referenz
- BibTeX
Hess, A., Jung, M. & Schäfer, G.,
(2003).
Combining multiple intrusion detection and response technologies in an active networking based architecture.
In:
Knop, J. V., Haverkamp, W. & Jessen, E.
(Hrsg.),
Security, E-learning, E-Services, 17. DFN-Arbeitstagung über Kommunikationsnetze.
Bonn:
Gesellschaft für Informatik e.V..
(S. 153-165).
@inproceedings{mci/Hess2003,
author = {Hess, Andreas AND Jung, M. AND Schäfer, Günter},
title = {Combining multiple intrusion detection and response technologies in an active networking based architecture},
booktitle = {Security, E-learning, E-Services, 17. DFN-Arbeitstagung über Kommunikationsnetze},
year = {2003},
editor = {Knop, Jan Von AND Haverkamp, Wilhelm AND Jessen, Eike} ,
pages = { 153-165 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Hess, Andreas AND Jung, M. AND Schäfer, Günter},
title = {Combining multiple intrusion detection and response technologies in an active networking based architecture},
booktitle = {Security, E-learning, E-Services, 17. DFN-Arbeitstagung über Kommunikationsnetze},
year = {2003},
editor = {Knop, Jan Von AND Haverkamp, Wilhelm AND Jessen, Eike} ,
pages = { 153-165 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
| Dateien | Groesse | Format | Anzeige | |
|---|---|---|---|---|
| GI-Proceedings.44.innen-6.pdf | 295.3Kb | Öffnen |
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 3-88579-373-3
ISSN: 1617-5468
Datum: 2003
Sprache:
(en)
(en)
Typ: Text/Conference Paper

