DocumentCode
1389013
Title
Sharing information for event analysis over the wide Internet
Author
Nagao, Masahiro ; Koide, Kazuhide ; Satoh, Akihiro ; Keeni, Glenn Mansfield ; Shiratori, Norio
Author_Institution
Graduate School of Information Sciences, Tohoku University, Sendai, Japan
Volume
12
Issue
4
fYear
2010
Firstpage
382
Lastpage
394
Abstract
Cross-domain event information sharing is a topic of great interest in the area of event based network management. In this work we use data sets which represent actual attacks in the operational Internet. We analyze the data sets to understand the dynamics of the attacks and then go onto show the effectiveness of sharing incident related information to contain these attacks. We describe universal data acquisition system for event based management (UniDAS), a novel system for secure and automated cross-domain event information sharing. The system uses a generic, structured data format based on a standardized incident object description and exchange format (IODEF). IODEF is an XML-based extensible data format for security incident information exchange. We propose a simple and effective security model for IODEF and apply it to the secure and automated generic event information sharing system UniDAS. We present the system we have developed and evaluate its effectiveness.
Keywords
Backscatter; Computer crime; Grippers; Information management; Internet; Monitoring; Backscatter; darknet; event based network management; event information sharing; incident object description and exchange format (IODEF); network management system; worm propagation;
fLanguage
English
Journal_Title
Communications and Networks, Journal of
Publisher
ieee
ISSN
1229-2370
Type
jour
DOI
10.1109/JCN.2010.6388475
Filename
6388475
Link To Document