TY - JOUR
T1 - Sharing information for event analysis over the wide internet
AU - Nagao, Masahiro
AU - Koide, Kazuhide
AU - Satoh, Akihiro
AU - Keeni, Glenn Mansfield
AU - Shiratori, Norio
PY - 2010/8
Y1 - 2010/8
N2 - Cross-domain event information sharing is a topic of great interest in the area of event based network management. In this work we use data sets which represent actual attacks in the operational Internet. We analyze the data sets to understand the dynamics of the attacks and then go onto show the effectiveness of sharing incident related information to contain these attacks. We describe universal data acquisition system for event based management (UniDAS), a novel system for secure and automated crossdomain event information sharing. The system uses a generic, structured data format based on a standardized incident object description and exchange format (IODEF). IODEF is an XML-based extensible data format for security incident information exchange. We propose a simple and effective security model for IODEF and apply it to the secure and automated generic event information sharing system UniDAS. We present the system we have developed and evaluate its effectiveness.
AB - Cross-domain event information sharing is a topic of great interest in the area of event based network management. In this work we use data sets which represent actual attacks in the operational Internet. We analyze the data sets to understand the dynamics of the attacks and then go onto show the effectiveness of sharing incident related information to contain these attacks. We describe universal data acquisition system for event based management (UniDAS), a novel system for secure and automated crossdomain event information sharing. The system uses a generic, structured data format based on a standardized incident object description and exchange format (IODEF). IODEF is an XML-based extensible data format for security incident information exchange. We propose a simple and effective security model for IODEF and apply it to the secure and automated generic event information sharing system UniDAS. We present the system we have developed and evaluate its effectiveness.
KW - Backscatter
KW - Darknet
KW - Event based network management
KW - Event information sharing
KW - Incident object description and exchange format (iodef)
KW - Network management system
KW - Worm propagation
UR - http://www.scopus.com/inward/record.url?scp=77956568411&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=77956568411&partnerID=8YFLogxK
M3 - Article
AN - SCOPUS:77956568411
SN - 1229-2370
VL - 12
SP - 382
EP - 394
JO - Journal of Communications and Networks
JF - Journal of Communications and Networks
IS - 4
ER -