Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
First iPhone worm spreads Rick Astley wallpaper
Four reasons to buy (and one reason to avoid) the Droid
Stimulus for tech and telecom $3B, but jobs still guesswork
Cisco MARS shuts out new third-party security devices
Verizon Droid buzz muted in Boston
Week in Google news: Google Dashboard, Droid fever, focus on e-commerce
Cloud computing, virtualization proponents getting antsy
Data center start-up offers energy saving software
Vendors scrambling to fix bug in Net's security
Judge dismisses lawsuit challenging Gartner's Magic Quadrant
Boston Celtics clamp down on spam
Cloud computing inevitable? Not so fast, educator says
Blue Coat slashes staff, buys S7 services company
Apple seeks new sheriff to lock up iPhones
/

Sound the alarm!

IETF working group seeks to improve security alerting.

Today's breaking news
Send to a friendFeedback


MINNEAPOLIS - An IETF working group has stepped up work on a protocol for broadcasting alerts of network breaches across proprietary security applications.

The Intrusion Detection Message Exchange Protocol (IDMEP) would let applications - and system managers - quickly share information about attacks, according to IDMEP working group members. They are meeting here as part of an overall IETF conference.

"[IDMEP] will be useful for attacks launched from one domain to another," says working group attendee Brian Tung, a computer scientist at the University of Southern California's Information Sciences Institute. "If a source domain notices an attack, it can notify the destination network. Right now, that's done by a human."

The group had met last year at the IETF meeting in Orlando, but was unsuccessful in gaining consensus and had to revamp its plans. This time, meeting attendees seemed encouraged by the group's efforts.

With the protocol, which could be based on SNMP Version 3, an alert detailing the type of attack in progress will be automatically sent across the network, along with a reference, such as a URL or a system file, where the network manager can find further information. That information could be the threshold setting of the alerter's system letting the recipient know what the alerter considers an attack or what the alerter suggests as a response for such an attack.

Mark Wood, product line manager at Internet Security Systems in Atlanta, says IDMEP could dramatically improve responses to attacks because networks will be sharing information, not duplicating efforts.

In fact, Tung says that hooking the IDMEP to policy networks could let users set up automatic responses to alerts and, therefore, ward them off.

"There are a number of dollars to be had in [the intrusion detection tools] market," says Stuart Staniford-Chen, co-chair of the working group. In fact, the projected market for intrusion detection tools is expected to be $200 million, according to analysts at the Aberdeen Group, a Boston consultancy. "Therefore, we need to get moving on this [protocol]."

Wood says he expects the protocol to be completed by the middle of next year, but products based on a proposed standard could be released as early as the first quarter of next year. Cisco and Axent are also working on the protocol.

RELATED LINKS

Contact Senior Online Reporter Sandra Gittlen

Intrusion-Detection Working Group
The IETF working group. Site has background info and a mailing-list archive.

Securing your IP network future
Network World, 2/23/98.

Common Intrusion Detection Framework
An earlier effort to develop an intrustion alert protocol.

Intrusion Detection Systems
Links to research projects and commercial apps.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.