Title :
DECIDUOUS: decentralized source identification for network-based intrusions
Author :
Chang, H.Y. ; Narayan, R. ; Wu, S.F. ; Vetter, B.M. ; Wang, X. ; Brown, M. ; Yuill, J.J. ; Sargor, C. ; Jou, F. ; Gong, F.
Author_Institution :
Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
Abstract :
DECIDUOUS is a security management framework for identifying the sources of network-based intrusions. The first key concept in DECIDUOUS is dynamic security associations, which efficiently and collectively provide location information for attack sources. DECIDUOUS is built on top of the IETF´s IPSEC/ISAKMP infrastructure, and it does not introduce any new network protocol for source identification in a single administrative domain. It defines a collaborative protocol for inter-domain attack source identification. The second key concept in DECIDUOUS is the management information integration of the intrusion detection system (IDS) and attack source identification system (ASIS) across different protocol layers. For example, in DECIDUOUS, it is possible for a network-layer security control protocol (e.g., IPSEC) to collaborate with an application-layer intrusion detection system module (e.g., IDS for the SNMP engine). In this paper, we present the motivations, design, and prototype implementation of the DECIDUOUS framework
Keywords :
Internet; computer network management; protocols; security of data; telecommunication security; DECIDUOUS; IETF; IPSEC/ISAKMP infrastructure; attack source identification system; collaborative protocol; decentralized source identification; dynamic security associations; intrusion detection system; management information integration; network-based intrusions; security management framework; Collaboration; Computer science; Control systems; Information security; Intrusion detection; Network topology; Project management; Protection; Protocols; Prototypes;
Conference_Titel :
Integrated Network Management, 1999. Distributed Management for the Networked Millennium. Proceedings of the Sixth IFIP/IEEE International Symposium on
Conference_Location :
Boston, MA
Print_ISBN :
0-7803-5748-5
DOI :
10.1109/INM.1999.770717