Question: DARPA's Common Intrusion Detection Framework (CIDF) and the IDWG effort to refine the CIDF and get it commercially accepted
"Dr. Robert G. Rains" <[email protected]> Mon, 30 Jan 2006 23:45:45 -0500
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Organization | The MITRE Corporation |
| Message-ID | <[email protected]> |
Gentlemen, I have a question regarding a "standard" that apparently originated at DARPA in the late 90's and then transitioned from DARPA to the IDWG so that the IDWG could refine the specification and further its acceptance. The "standard" is the Defense Advanced Research Program Agency (DARPA) "Common Intrusion Detection Framework" (CIDF). I'm working on standards for Anti-Terrorism/Force Protection (AT/FP), and an integration contractor has proposed that the DoD adopt the "DARPA Intrusion Detection Systems" aka "Common Intrusion Detection Framework" (CIDF) as a "standard" to be imposed on AT/FP systems. MY CURRENT UNDERSTANDING It appears that the standard titled, "DARPA Intrusion Detection Systems (Network)" is not a standard. It seems to be an area of research. Although DARPA has funded some leading edge research into concepts for intrusion detection, DARPA is not currently the lead for development of standards related to intrusion detection. An April 1999 DARPA report stated, "... intrusion detection systems must be able to interoperate with security screens, such as network firewalls, and with response mechanisms that can be used to contain and/or mitigate the effects of an attack. To enable such interoperation, DARPA has developed a Common Intrusion Detection Framework that allows network components to exchange information and to work together to respond to network-based attacks. The Internet Engineering Task Force, the organization that maintains the standards that govern the Internet, will refine the specification and further its acceptance." I understand that the standards portion of t! he activity was being pursued under the auspices of the IETF. A somewhat dated history of the CIDF effort may be found at http://www.isi.edu/gost/cidf. However, many of the organizational references, e-mail addresses, and URLs on that page are now out of date. Development of intrusion detection standards was being pursued by the Intrusion Detection Exchange Format Working Group (idwg) of the Internet Engineering Task Force (IETF). However, in the e-mail chain below, Sam Hartman states, "Based on my own conclusions and on the strong opinions of other area directors I've consulted with, IDWG no longer constitutes an active working group. There is an insufficient core of active participants--particularly participants not involved in the document--to generate an informed consensus on changes." QUOTE FROM THE CONTRACTOR SUBMITTAL PROPOSING THE CIDF AS A STANDARD The Defense Advanced Research Program Agency (DARPA) "Common Intrusion Detection Framework" (CIDF) specifies a set of concepts and guidelines that provide a framework within which Intrusion Detection Systems (IDS) can be understood, compared and designed. An IDS system's architecture, capabilities and features can be defined in relation to relationships with the DARPA CIDF. The IETF has formed an Intrusion Detection Working Group (IDWG) that is also providing guidance in regard to IDS standards. The Gartner Groups "Seven Key Selection Criteria for Network Intrusion Prevention Systems (IPS)" is also a valuable framework for IDS and IPS. The OASIS Security Assertion Markup Language (SAML 2.0) also relates to standard security measures. REFERENCES 1) http://www.toplayer.com/pdf/GartnerBrief.pdf 2) http://www.isi.edu/gost/cidf/ 3) http://www.isi.edu/gost/cidf/drafts/communication.txt 4) http://www.isi.edu/gost/cidf/drafts/language.txt 5) http://www.isi.edu/gost/cidf/tutorial.html 6) http://www.isi.edu/gost/cidf/drafts/api.txt 7) http://www.ietf.org/internet-drafts/draft-ietf-idwg-requirements-10.txt 8) http://www.ietf.org/internet-drafts/draft-ietf-idwg-idmef-xml-12.txt 9) http://www.ietf.org/internet-drafts/draft-ietf-idwg-beep-idxp-07.txt 10) http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security MY CURRENT CONCLUSION In conclusion... I don't see any evidence that the DARPA CIDF ever became a commercially accepted standard. None of the above references seem to refer to a DARPA web site or to a mature, commercially accepted standard. I understand that, at this time, the IDWG is for all practical purposes, not an active working group. It appears that this is an area of research that DARPA was interested in for awhile back in the late 90's, and for which DARPA eventually gave responsibility to the IETF to refine the "standard" and seek its acceptance. It isn't clear that the CIDF ever became a mature, commercially accepted "standard" which would lead to commercial products that comply with the standard being developed and placed on the market. I would sincerely welcome any additional information that you might have which would shed light on the status of the CIDF. ONE LAST QUESTION: Did draft-ietf-idwg-idmef-xml-14 expire on 31 July 2005, or has it been adopted as a standard? To the best of your knowledge, are at least two different commercial organizations developing products based on this draft standard? Thanks in advance, Robert Rains ***************************************************************** Robert G. Rains, Ph.D. Force Protection C2 Systems Engineer Electronic Systems Center Force Protection Systems Squadron, FPSS/FPTE 5 Eglin St, Bldg 1624 Hanscom AFB, MA 01731-2100 Phone: 781-377-4744 E-Mail: [email protected] ***************************************************************** =============================================================