IDS Standards: Lessons Learned to Date

نویسنده

  • Stuart Staniford-Chen
چکیده

Stuart Staniford-Chen received his PhD in Physics and Masters in Computer Science from the University of California at Davis. There he joined the computer security group and worked on methods to trace intruders across the Internet, and led the team that developed the GrIDS hierarchical intrusion detection system. DARPA asked Dr Staniford-Chen to start and lead the Common Intrusion Detection Framework (CIDF) working group; he was chair or co-chair of that group until the beginning of this year. He is now a co-chair of the IETF's working group to standardize IDS alerts. Dr Staniford-Chen now works for his own research and consulting company, Silicon Defense. Abstract: I will discuss two efforts to get Intrusion Detection Systems to work together-the Common Intrusion Detection Framework (CIDF), and the IETF's working group to develop an Intrusion Detection Exchange Format (IDEF). CIDF is an effort started and supported by DARPA to develop a common language and means of interchange for IDS systems to share any data that they might need to share (a very ambitious scope). The focus has been on allowing systems developed by DARPA researchers to interoperate with one another. CIDF expresses events using a language which has an English-like syntax, though highly restricted and formalized. The sentences are denoted as S-expressions with explicit parse-trees. A large vocabulary of terms are defined for expressing things that IDS systems might need to talk about (files, processes, network packets, etc). The semantics of these terms is expressed in English (as opposed to using logic, for example). Additionally, CIDF defines an encoding for expressing these sentences in a compact way, and protocols and APIs for exchanging them. I'll talk about what is hard about doing this. Defining a common syntax, encoding, and protocols for exchange is easy. There are many fine solutions. What is hard is agreeing on the semantics of language vocabulary. In CIDF, this means agreeing on an ontology for the computational world that IDS systems observe and report on. This is very hard. The design of this language has changed continually through out the life of the CIDF working group, and while the current version is a vast improvement on early versions, it retains some ambiguities. Also, while CIDF was designed to be extensible by adding new vocabulary, it appears that extensions never get easy. Since most of the work is vocabulary design, it's always a substantial effort to extend the language …

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Important Lessons Learned From Nearly a Half-Century of Orthopedic Practice

“Those who cannot remember the past are condemned to repeat it” [1]. The famous quote from Hispanic American philosopher George Santayana reminds us of the critical importance of constantly reflecting on the most important lessons garnered from both our own personal experiences and those of our peers. In 49 years of academic orthopedic practice, I have frequently reflected on the most important...

متن کامل

Regionalization of the Iowa State University Extension System: Lessons Learned by Key Administrators

The cyclical economic downturn in the United States has forced many Extension administrators to rethink and adjust services and programming. The Cooperative Extension System (CES), the organization primarily responsible for governmental Extension work in the United States, at Iowa State University responded to this economic downturn by restructuring its organization from county based to a regio...

متن کامل

Rebirth of a city lessons learned from post disaster reconstruction the case study: Rofayye\'

After disasters, one of the main challenges confronting authorities is site selection for reconstructing damaged structures. Experiences indicate that appropriate policies in site-selection could greatly influence on reconstruction success and residents' satisfaction. Meanwhile, in literature related to post disaster reconstruction, avoiding from relocating settlements is generally emphasize...

متن کامل

Psychosocial Rehabilitation: Some Lessons Learned From Natural Disaster in Iran

Background: Disasters have adverse impacts on different aspects of human life. Psychosocial Rehabilitation is one of the fields which is usually overshadowed and ignored by physical rehabilitation or its importance does not receive proper attention. This research attempts to study some lessons learned from Psychosocial Rehabilitation based on disaster experiences in Iran. M...

متن کامل

Lessons Learned in Implementing the Extended Date/Time Format in a Large Digital Library

In 2012, the University of North Texas (UNT) Libraries implemented the Library of Congress Extended Date/Time Format (EDTF) into the metadata guidelines for their digital holdings which now contain more than 460,000 records. This paper discusses the evaluation process to identify the number of previously-existing dates that meet EDTF standards and those that need to be edited for conformance. I...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1999