DocumentCode
2868669
Title
DECIDUOUS: decentralized source identification for network-based intrusions
Author
Chang, H.Y. ; Narayan, R. ; Wu, S.F. ; Vetter, B.M. ; Wang, X. ; Brown, M. ; Yuill, J.J. ; Sargor, C. ; Jou, F. ; Gong, F.
Author_Institution
Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
fYear
1999
fDate
1999
Firstpage
701
Lastpage
714
Abstract
DECIDUOUS is a security management framework for identifying the sources of network-based intrusions. The first key concept in DECIDUOUS is dynamic security associations, which efficiently and collectively provide location information for attack sources. DECIDUOUS is built on top of the IETF´s IPSEC/ISAKMP infrastructure, and it does not introduce any new network protocol for source identification in a single administrative domain. It defines a collaborative protocol for inter-domain attack source identification. The second key concept in DECIDUOUS is the management information integration of the intrusion detection system (IDS) and attack source identification system (ASIS) across different protocol layers. For example, in DECIDUOUS, it is possible for a network-layer security control protocol (e.g., IPSEC) to collaborate with an application-layer intrusion detection system module (e.g., IDS for the SNMP engine). In this paper, we present the motivations, design, and prototype implementation of the DECIDUOUS framework
Keywords
Internet; computer network management; protocols; security of data; telecommunication security; DECIDUOUS; IETF; IPSEC/ISAKMP infrastructure; attack source identification system; collaborative protocol; decentralized source identification; dynamic security associations; intrusion detection system; management information integration; network-based intrusions; security management framework; Collaboration; Computer science; Control systems; Information security; Intrusion detection; Network topology; Project management; Protection; Protocols; Prototypes;
fLanguage
English
Publisher
ieee
Conference_Titel
Integrated Network Management, 1999. Distributed Management for the Networked Millennium. Proceedings of the Sixth IFIP/IEEE International Symposium on
Conference_Location
Boston, MA
Print_ISBN
0-7803-5748-5
Type
conf
DOI
10.1109/INM.1999.770717
Filename
770717
Link To Document