★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/intrusion_detection_article-3243.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Intrusion Detection 6/28/2001 13:07

Eliminating IDS Babble

InfoSec Magazine
Posted By: Jen Olson
6/28/2001

Simply put, there are as many different IDS applications as there are attack vectors (figuratively speaking, of course). As many organizations have discovered, multiple IDS solutions are needed to monitor different platforms and networks. This diversity inhibits enterprise-wide pooling and correlation of attack data. Although its work is far from complete, the Intrusion Detection Exchange Format working group (IDWG) in April released a revised draft of its Intrusion Alert Protocol (IAP). The group eventually hopes to create a protocol that will enable the easy exchange and analysis of attack data from multiple IDSes.

The specification authors write that IAP will support "the transmission of alert data from an intrusion detection sensor/analyzer, which detects a potential intrusion, to a manager, that displays the alert to a human, logs it to a database or takes appropriate action."


Click here to go to this article.

Stemming the DoS flood
Jul 2

Misgivings remain after workplace privacy conference
Jul 2

Encrypted Tunnels using SSH and MindTerm HOWTO
Jul 2

Kernel Security Extensions USENIX BOF Summary
Jul 2

Online firms in a fluster over privacy law
Jul 2

Too Much Focus On Hackers, Warns Security Expert
Jul 2

A Matter of Power
Jul 2

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000