Nothing Special   »   [go: up one dir, main page]

skip to main content
10.1145/1852666.1852721acmotherconferencesArticle/Chapter ViewAbstractPublication PagescsiirwConference Proceedingsconference-collections
research-article

A service model for network security applications

Published: 21 April 2010 Publication History

Abstract

We describe a new architecture designed to outsource the complexity of configuring, deploying and operating network security monitoring systems. Our architecture is designed to allow the concurrent operation of best-of-breed network security applications which include flow analysis, Intrusion Detection Systems (IDS), passive Operating System (OS) fingerprinting and application-level service discovery. In addition, we introduce a new framework for the inclusion of network security intelligence data into the security event correlation. We also provide some preliminary quantification of the effectiveness of this new framework.

Supplementary Material

Supplemental material. (a50-ricciulli_slides.pdf)

References

[1]
Privacy Impact Assessment for Einstein 2, US_CERT http://www.dhs.gov/xlibrary/assets/privacy/privacy_pia_einstein2.pdf
[2]
Common Event Format, Arcsigth Inc, http://www.arcsight.com/solutions/solutions-cef/
[3]
Sourcefire Vulnerability Research Team, SourceFire Inc., http://www.snort.org/vrt
[4]
Emerging Threats, Matt Jonkman, http://www.emergingthreats.net/
[5]
NetFlow Version 9 Flow-Record Format, Cisco System, http://www.cisco.com/en/US/technologies/tk648/tk362/technologies_white_paper09186a00800a3db9.html
[6]
BotHunter Internet Distribution Page, SRI International, http://www.bothunter.net/
[7]
P0f, William Stearns, http://freshmeat.net/projects/p0f/
[8]
Highly Predictive Blacklisting, Jian Zhang, Phillip Porras, Johannes Ullrich SRI Interntional and the SANS Institute, Usenix Security, August 2008
[9]
DPI - Deep Packet Inspection, 10Gbps Platforms for Network Policy Enforcement, Network Security, Cyber Security, Open Source Software Platform | Bivio Networks, Bivio Networks, http://www.bivio.net/products/dpi/

Cited By

View all
  • (2014)A Big Data Architecture for Large Scale Security MonitoringProceedings of the 2014 IEEE International Congress on Big Data10.1109/BigData.Congress.2014.18(56-63)Online publication date: 27-Jun-2014

Recommendations

Comments

Please enable JavaScript to view thecomments powered by Disqus.

Information & Contributors

Information

Published In

cover image ACM Other conferences
CSIIRW '10: Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research
April 2010
257 pages
ISBN:9781450300179
DOI:10.1145/1852666
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 21 April 2010

Permissions

Request permissions for this article.

Check for updates

Author Tags

  1. anomaly detection
  2. cloud computing
  3. cyber-security
  4. honeypot
  5. intrusion detection
  6. management system
  7. network security
  8. sensor

Qualifiers

  • Research-article

Conference

CSIIRW '10

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)6
  • Downloads (Last 6 weeks)0
Reflects downloads up to 29 Sep 2024

Other Metrics

Citations

Cited By

View all
  • (2014)A Big Data Architecture for Large Scale Security MonitoringProceedings of the 2014 IEEE International Congress on Big Data10.1109/BigData.Congress.2014.18(56-63)Online publication date: 27-Jun-2014

View Options

Get Access

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media