• DocumentCode
    1178802
  • Title

    Hi-DRA: Intrusion Detection for Internet Security

  • Author

    Kemmerer, Richard A. ; Vigna, Giovanni

  • Author_Institution
    Reliable Software Group, California Univ., Santa Barbara, CA, USA
  • Volume
    93
  • Issue
    10
  • fYear
    2005
  • Firstpage
    1848
  • Lastpage
    1857
  • Abstract
    Intrusion detection systems monitor computer networks looking for evidence of malicious actions. Networks are complex systems, and a comprehensive intrusion detection solution has to be able to manage event streams with different content,speed, level of abstraction, and accessibility. Therefore, it is necessary to distribute intrusion detection sensors across multiple protected networks, manage their configuration as the security posture of the networks changes, and process the results of their analysis so that a high-level picture of the security state of the network can be provided to the administrators. This paper presents Hi-DRA, a network surveillance, analysis, and response system for high-speed WANs. The system provides a framework for the modular development of intrusion detection sensors in heterogeneous, high-speed environments. In addition, the system provides an infrastructure that supports the dynamic configuration of the sensors and the collection and interpretation of their results. The system, as a whole,is able to provide fine-grained monitoring across WANs and, at the same time,is able to correlate the results of the analysis of the different sensors into a high-level expressive description of security violations.
  • Keywords
    authorisation; telecommunication security; wide area networks; Hi-DRA; Internet security; alert correlation; anomaly detection; computer networks; computer security; heterogeneous/high-speed environments; high-speed wide area networks; intrusion detection; misuse detection; multiple protected networks; network analysis; network response system; network security; network surveillance; Computer network management; Computerized monitoring; Content management; Internet; Intrusion detection; Protection; Security; Sensor phenomena and characterization; Sensor systems; Surveillance; Alert correlation; anomaly detection; computer security; intrusion detection; misuse detection; network security; security;
  • fLanguage
    English
  • Journal_Title
    Proceedings of the IEEE
  • Publisher
    ieee
  • ISSN
    0018-9219
  • Type

    jour

  • DOI
    10.1109/JPROC.2005.853547
  • Filename
    1512502