• DocumentCode
    1563717
  • Title

    A new paradigm for intrusion detection systems

  • Author

    Pressley, Tony

  • fYear
    2002
  • fDate
    6/24/1905 12:00:00 AM
  • Firstpage
    390
  • Abstract
    Summary form only given. The US Army Research Laboratory through its Information Assurance Center (IAC) seeks to evolve and continuously develop an IA capability that sets the Army and DoD standard for protecting computing and communications infrastructure from unauthorized access, illicit exploitation, component damage, and denial of service to authorized users. The IAC has two components, an operational computer emergency response team that monitors a major Department of Defense research network on a 27 × 7 basis, and a research component. Unlike many similar activities, the ARL computer emergency response team employs multiple network intrusion detection system tools to accomplish its mission, and serves as a testbed for IDS tools transitioning from universities and industry into the government and commercial sectors. The IAC\´s in-house research component is focused on architecture improvements to promote data fusion across sensors and time. Issues which the new architecture address include timeliness, archiving issues, and the incorporation of both signature and anomaly IDS tools into the architecture and the fusion of the information resulting from these different approaches. The IAC has a number of collaborations with industry and academia to promote IDS tools/methodologies focused on network surveillance, intrusion detection systems focused on advanced networking (OC12 and above), and the "insider threat".
  • Keywords
    computer networks; emergency services; military communication; military computing; military standards; safety systems; security of data; sensor fusion; telecommunication security; telecommunication standards; ARL computer emergency response team; Army standard; Department of Defense research network; DoD standard; IAC; IDS tools; IDS tools/methodologies; Information Assurance Center; OC12; US Army Research Laboratory; advanced networking; archiving; commercial sector; communications infrastructure; component damage; computer emergency response team; computing infrastructure; data fusion; denial of service; government sector; illicit exploitation; industry; insider threat; intrusion detection systems; network intrusion detection system tools; network surveillance; sensors; testbed; timeliness; unauthorized access protection; universities; Communication standards; Computer crime; Computer displays; Computer networks; Educational institutions; Intrusion detection; Military computing; Protection; Standards development; System testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks, 2002. Proceedings. Eleventh International Conference on
  • ISSN
    1095-2055
  • Print_ISBN
    0-7803-7553-X
  • Type

    conf

  • DOI
    10.1109/ICCCN.2002.1206523
  • Filename
    1206523