Re: Question: DARPA's Common Intrusion Detection Framework (CIDF)and the IDWG effort to refine the CIDF and get it commercially accepted
[email protected] Tue, 31 Jan 2006 08:30:44 -0500
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <OFA448F003.0BBB7D36-ON85257107.0049FD1D-85257107.004A39AB@stonesoft.com> |
I agree 100% with Felix. The number of permutations of vendors in the space covered by the interoperability framework is much, much larger now than it ever was before. There are more firewall vendors, IDS/IPS vendors, and more switch/router vendors with security modules embedded in their cores that some standard would serve network security overall now more than ever. My own opinion, not necessarily that of my employer. Standard disclaimers apply. --- Mark Boltz, Sr. Sales Engineer [email protected] http://www.stonesoft.com Toll Free: 1.866.869.4075 DID: 1.703.584.5225 Fax: 1.703.288.4811 Cell: 1.571.218.2481 8133 Leesburg Pike, Suite 610 Vienna, VA 22182-2730 USA |---------+---------------------------> | | "S. Felix Wu" | | | <[email protected]| | | du> | | | Sent by: | | | owner-idwg-l@hmc| | | .edu | | | | | | | | | 01/31/2006 01:44| | | AM | | | Please respond | | | to wu | | | | |---------+---------------------------> >-----------------------------------------------------------------------------------------------------------------------| | | | To: "Dr. Robert G. Rains" <[email protected]> | | cc: Sam Hartman <[email protected]>, [email protected], [email protected], "B. Feinstein (TNT)" | | <[email protected]>, [email protected] | | Subject: Re: Question: DARPA's Common Intrusion Detection Framework (CIDF)and the IDWG effort to refine | | the CIDF and get it commercially accepted | >-----------------------------------------------------------------------------------------------------------------------| Robert, Your conclusion is mostly correct. CIDF was a DARPA funded research effort leaded by Stuart Staniford and many other DARPA PI's in late 90. The objective was to standardize it via the IETF process. However, the first BOF in LA, I still remember, was not very well received by the audience due to the potential complexity and expressiveness of s-expressions. But, it was clear from the BOF that there was a significant interest in having an industry standard. Therefore, the IDWG working group was formed, and Stuart and Mike were the first chairs for the working group. IDWG basically abandoned CIDF and S-expression (at least initially) and started from "requirement study". We then ran into the debate of issues such as SNMP versus XML. S-expression was not discussed very much after that point. I personally believe that an industry standard is still needed as we have many more powerful networ/host IDS systems today. And, from the research community, I feel that we know a lot better about what should be standardized than say 7~8 years ago. And, I see a critical need for interoperability and inter-domain security operations now and in the future. I think we should think about all the issues again. -Felix Dr. Robert G. Rains wrote: > Gentlemen, > > I have a question regarding a "standard" that apparently originated at > DARPA in the late 90's and then transitioned from DARPA to the IDWG so > that the IDWG could refine the specification and further its > acceptance. The "standard" is the Defense Advanced Research Program > Agency (DARPA) "Common Intrusion Detection Framework" (CIDF). I'm > working on standards for Anti-Terrorism/Force Protection (AT/FP), and an > integration contractor has proposed that the DoD adopt the "DARPA > Intrusion Detection Systems" aka "Common Intrusion Detection Framework" > (CIDF) as a "standard" to be imposed on AT/FP systems. > > MY CURRENT UNDERSTANDING > It appears that the standard titled, "DARPA Intrusion Detection Systems > (Network)" is not a standard. It seems to be an area of research. > Although DARPA has funded some leading edge research into concepts for > intrusion detection, DARPA is not currently the lead for development of > standards related to intrusion detection. An April 1999 DARPA report > stated, "... intrusion detection systems must be able to interoperate > with security screens, such as network firewalls, and with response > mechanisms that can be used to contain and/or mitigate the effects of an > attack. To enable such interoperation, DARPA has developed a Common > Intrusion Detection Framework that allows network components to exchange > information and to work together to respond to network-based attacks. > The Internet Engineering Task Force, the organization that maintains the > standards that govern the Internet, will refine the specification and > further its acceptance." I understand that the standards portion of t! > he activity was being pursued under the auspices of the IETF. A > somewhat dated history of the CIDF effort may be found at > http://www.isi.edu/gost/cidf. However, many of the organizational > references, e-mail addresses, and URLs on that page are now out of > date. Development of intrusion detection standards was being pursued > by the Intrusion Detection Exchange Format Working Group (idwg) of the > Internet Engineering Task Force (IETF). However, in the e-mail chain > below, Sam Hartman states, "Based on my own conclusions and on the > strong opinions of other area directors I've consulted with, IDWG no > longer constitutes an active working group. There is an insufficient > core of active participants--particularly participants not involved in > the document--to generate an informed consensus on changes." > > QUOTE FROM THE CONTRACTOR SUBMITTAL PROPOSING THE CIDF AS A STANDARD > The Defense Advanced Research Program Agency (DARPA) "Common Intrusion > Detection Framework" (CIDF) specifies a set of concepts and guidelines > that provide a framework within which Intrusion Detection Systems (IDS) > can be understood, compared and designed. An IDS system's architecture, > capabilities and features can be defined in relation to relationships > with the DARPA CIDF. The IETF has formed an Intrusion Detection Working > Group (IDWG) that is also providing guidance in regard to IDS > standards. The Gartner Groups "Seven Key Selection Criteria for Network > Intrusion Prevention Systems (IPS)" is also a valuable framework for IDS > and IPS. The OASIS Security Assertion Markup Language (SAML 2.0) also > relates to standard security measures. > > REFERENCES > 1) http://www.toplayer.com/pdf/GartnerBrief.pdf > 2) http://www.isi.edu/gost/cidf/ > 3) http://www.isi.edu/gost/cidf/drafts/communication.txt > 4) http://www.isi.edu/gost/cidf/drafts/language.txt > 5) http://www.isi.edu/gost/cidf/tutorial.html > 6) http://www.isi.edu/gost/cidf/drafts/api.txt > 7) > http://www.ietf.org/internet-drafts/draft-ietf-idwg-requirements-10.txt > 8) http://www.ietf.org/internet-drafts/draft-ietf-idwg-idmef-xml-12.txt > 9) http://www.ietf.org/internet-drafts/draft-ietf-idwg-beep-idxp-07.txt > 10) http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security > > > MY CURRENT CONCLUSION > In conclusion... I don't see any evidence that the DARPA CIDF ever > became a commercially accepted standard. None of the above references > seem to refer to a DARPA web site or to a mature, commercially accepted > standard. I understand that, at this time, the IDWG is for all > practical purposes, not an active working group. It appears that this > is an area of research that DARPA was interested in for awhile back in > the late 90's, and for which DARPA eventually gave responsibility to the > IETF to refine the "standard" and seek its acceptance. It isn't clear > that the CIDF ever became a mature, commercially accepted "standard" > which would lead to commercial products that comply with the standard > being developed and placed on the market. > > I would sincerely welcome any additional information that you might have > which would shed light on the status of the CIDF. > > ONE LAST QUESTION: > Did draft-ietf-idwg-idmef-xml-14 expire on 31 July 2005, or has it been > adopted as a standard? To the best of your knowledge, are at least two > different commercial organizations developing products based on this > draft standard? > > Thanks in advance, > > Robert Rains > > ***************************************************************** > Robert G. Rains, Ph.D. > Force Protection C2 Systems Engineer > Electronic Systems Center > Force Protection Systems Squadron, FPSS/FPTE > 5 Eglin St, Bldg 1624 > Hanscom AFB, MA 01731-2100 > Phone: 781-377-4744 > E-Mail: [email protected] > ***************************************************************** > > ============================================================= > >