DocumentCode :
2885330
Title :
Taichi: An Open Intrusion Automatic Response System Based on Plugin
Author :
Han, Hong ; Lu, Xian-Liang ; Ren, Li-Yong ; Chen, Bo
Author_Institution :
Coll. of Comput. Sci. & Eng., Univ. of Electron. Sci. & Technol. of China
fYear :
2006
fDate :
13-16 Aug. 2006
Firstpage :
66
Lastpage :
77
Abstract :
For most current intrusion detection systems, the capability to counterstrike network intrusion is limited. And the automatic protection of intranet is extremely difficult. In this paper, we present a system: TAICHI which combines heterogeneous intrusion detection systems with improved distributed firewall system (IDFS) to automatically detect and prevent intrusion originated from intranet or Internet. TAICHI can manage heterogeneous IDSs (intrusion detection systems) and firewalls with plugin, which makes it evolved easily to employ new detection technology and to integrate legacy firewall in an organization. ECA (extended common alert) in TAICHI can analyze alerts from heterogeneous IDSs. The system employs IDFS as a response subsystem, which could easily block attack originated from intranet or Internet. To configure heterogeneous firewalls efficiently, extended meta-firewall-rule configuration (EMFRC) was presented, which can not only configure firewall in a unified template, but also set special options of rules of different type with the same template. Due to EMFRC and IDFS, TAICHI makes the optimized strategy automatically to block intrusion from different network topology
Keywords :
Internet; authorisation; intranets; telecommunication security; Internet; automatic protection; distributed firewall system; intranet; intrusion detection system; meta-firewall-rule configuration; network topology; open intrusion automatic response system; Access control; Communication system control; Computer hacking; Computer science; Control systems; Cybernetics; Delay; Educational institutions; Electronic mail; Graphical user interfaces; Internet; Intrusion detection; Logic; Machine learning; Network topology; Protection; Technology management; Automatic intrusion response; Heterogeneous; Improved Distributed Firewall; extended meta-firewall-rule configuration;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Machine Learning and Cybernetics, 2006 International Conference on
Conference_Location :
Dalian, China
Print_ISBN :
1-4244-0061-9
Type :
conf
DOI :
10.1109/ICMLC.2006.258818
Filename :
4028035
Link To Document :
بازگشت