forwarded message from new list member
Mike Erlinger <[email protected]> Fri, 28 Jan 2005 11:55:00 -0800
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
the following came from a new member to the list (before they joined the
list).
mike
We are a team working in the field of Network and System Security at the
Centre for Development of Advance Computing(CDAC), Bangalore, India. We
have been following the IDMEF draft for the past two years and have found
it to be quite comprehensive and well thought out. This has prompted us to
use IDMEF as a message format for communication between the IDS entities
of our IDS. For this we are very grateful to the Intrusion Detection
Working Group.
Working on intrusion detection systems, we believe the latest version of
IDMEF(13) can be enhanced to facilitate even more comprehensive
communication between the IDS entities. Considering the present IDS
scenarios and their applications, one finds multiple IDS entities deployed
all over the network and across networks. In such an environment, the
entities would have much more to share than Alerts and Heartbeats.
During our work in the field of intrusion detection, we realised that
sharing information, about the entities themselves can make the system
more robust and survivable.
As IDMEF is supposed to fulfill all the requirements of format of
messages that could be exchanged among ID entities, we feel, there should
be some way to deal with "control information" that an ID entity would
like to send to other entities. Here, we would like to complement the set
of messages supported by IDMEF by a new group, which we call, "Control
Messages". The proposed group would consist of 5 sets of messages,
classified based on the kind of control message and the action expected
from the receivers viz., instructional, operational, announcements,
success and exception messages.
Since the information shared is neither an Alert category, nor a
HeartBeat, we propose to introduce a new heir of the IDMEF-Message.
"Control-Message" seems to be an appropriate name. Moreover, the
information cannot be sent using the existing IDMEF structure (either
Alert or Heartbeat). The Control-Message further can have hierarchy
similar to the one with Alert.
Certain advantages by having such control are:
a. Synchronization is achieved between the IDS entities
b. Entities can be better informed and be up-to-date about
co-operating ids-entities
c. Possibility of task delegation
d. Announcement of finer performance details of entities.
e. Operational status of entities
The position of the proposed "Control-Message" against the current
messages can be visualised as follows,
+---------------+
| IDMEF-Message |
+---------------+
/_\
|
+--------------+------------------+
| | |
+-------+ +-----------+ +-----------------+
| Alert | | Heartbeat | | Control-Message |
+-------+ +-----------+ +-----------------+
We look forward for your feedback on the proposal.
Thanks & regards,
srinivas.
--------------------------------------------------------------------------------------
Srinivas Guntupalli
Centre for Development of Advanced Computing,
Navi Mumbai 400614, India.
Phone: +91-22-27560013 Telefax: +91-22-27560004
Website: http://www.ncst.ernet.in
email:[email protected]
--
Mike Erlinger, Professor and Chair Computer Science
www: http://www.cs.hmc.edu/~mike
email: [email protected]
smail: Computer Science Dept., Harvey Mudd College,
301 E. 12th Street, Claremont, CA, 91711
909-621-8912, FAX: 909-607-8364