special issue on intrusion detection systems

1
Editorial Special issue on Intrusion Detection systems The last two years have seen some of the most signi®cant advances in network security while at the same time some of the most signi®cant developments have been in worms, viruses and distributed denial of service attacks. Whether network security architecture is keeping abreast of attack scenarios is a moot point. The mainstays of security are ®rewalls, cryptogrpahic engines, access control and Intru- sion Detection systems. There is no doubt that the ®rewall is a key component in the security architecture, although its reliability in the face of some of these attacks is somewhat problematic. It is clear that there is a range of attacks to which ®rewalls are of little useÐthe recent Code Red and Nimda worms being good examples. Implementation of security policy onto a ®rewall is a vital yet complex task. Firewalls are frequently very large and highly complex programs and overlaying this software with equally complex sets of rules based upon a company's security policy will inevitably lead to errors. Until recently ®rewall vendors showed little interest in accepting that their ®rewalls were vulnerable to attackÐwhether caused by mis-con®guration, errors in software design or just because ®rewalls are not able to detect all types of attacks. Now the idea of testing a security con®guration with Intrusion Detec- tion tools has become acceptable to ®rewall designers and vendors. Some now offer Intrusion Detection Tools as part of, in addition to, their ®rewall products. Although the science of Intrusion Detection testing is still very new, there has been considerable research into this technology. The main research areas include: modelling normal system behaviour with expert, arti®cial intelligence and statistically based systems. From these is possible to determine anonymous behaviour, including widely distrib- uted attacks, and to report attacks in realtime focusing on time critical and synchronised systems. This has led to advances in modelling methodologies, heuristic recognition of attacks, autoblocking as well as to better understand distributed denial of service attack ¯oods. A variety of systemsÐboth experimental and commercialÐare now available even though they lack standardisation and consis- tency in the results that they produce. The papers in this special issue on Intrusion Detection Systems address a range of pertinent issues. Some cover architectural and operational methodologies including reports on case study testing while others address issues such as agent-based intrusion detection systems, decentra- lised systems for detecting distributed attacks, and the use of mobile agents for detecting and responding to intrusions. Ray Hunt * Department of Computer Science, University of Canterbury, Private Bag 4800, Christchurch, New Zealand E-mail address: [email protected] 13 November 2001 Computer Communications 25 2002) 1355 0140-3664/02/$ - see front matter q 2002 Elsevier Science B.V. All rights reserved. PII: S0140-366402)00036-1 www.elsevier.com/locate/comcom * Corresponding author. Tel.: 164-3-3642347; fax: 164-3-3642569.

Upload: ray-hunt

Post on 02-Jul-2016

214 views

Category:

Documents


2 download

TRANSCRIPT

���������

����� � �� �� ����� ��� ��������� � ���

��� �� � ��� ���� ���� ��� ��� �� ��� �� � ���������

������� �� ������� ������� ����� �� ��� ��� ���� ��� ��

��� �� � ��������� ���������� ���� ���� �� ���� �

���� � ��� �� �������� ������ �� ������ ������ � �������

������� ������� ������������ � ������ ����� � �� ������

������� � � ���� ����� ��� ���� ��� �� ������� ���

������� � ����������� ������ � ���� ������� ��� �����

��� ��������� � ��� � ����� � �� ����� ���� ��� ������� �

� ��� �������� �� ��� ������� ������������� �������� ��

����������� �� ��� ���� �� ��� �� ��� � ������ � �������

����������� �� � ����� ���� ����� � � ����� �� ������ ��

����� ������� ��� �� ������ � �!��� ������ "��� #�� ���

$���� ���� ����� ���� �%���� �

������������� �� ������� ����� ���� � ������� � � �����

��� �����% �� �� &������� ��� ���'������ ���� ����� ���

������ �����% ������ ��� ���������� ��� ������� ����

�'����� �����% �� �� ���� �� �� ��� � ������(

������� ����� ���� ���������� ���� �� ����� � )���� ��������

������� ������ ����� ������ ������ � �� �������� ���� �����

������� ���� ���������� �� ������!������� ��� �� ��

�� ������������� ����� �� ������� �� ��� �� *� � ����� �

������� ��� ��� ���� �� ������ ��� ��� �� ������ � $�� ���

���� �� �� ���� � ������� ������������ ���� ����� ��� �����

���� ���� �� ������ ��������� �� ������� �� ����� ���

������ � ��� ��� ����� ����� ��� ��������� ���� � ���

��� �� �������� ��� ����� ������� ������ �

+������� ��� ������ �� ����� ��� ��������� �� ���� � ����

���� ���� ����� �� ���� ��� �������� �� ����� ���� ���

����������� ��� ���� �� ����� ���� �������, ���������

������ � ��� ��������� ���� �%���� ��������� ������������

��� ���� ������� �� �� � ��� � &��� ��� � � � ���� ��

��������� �������� ���������� ��������� ������ �� ����

���� ������ � ��� �� ����� ������ �� �������� ���� ��� ��

���� �������� ��� �������� �� � ��� � ��� �� ��� ��

������� �� ��������� ������������ � ����� ��� �����������

�� ������ � ������������ � ���� � �� ������ ����� ����

�� �������� ������ �� ������ ������ -��� � + ������� ��

� ��� !���� �%��������� ��� ����������!��� ���

��������� ���� ������ ���� ���� �������� ����� ��� ��� �

����� �� ��� �� ��� ���� ���� �������

��� ��� �� ��� ����� � �� �� ����� ��� ���������

� ��� ����� � ����� �� �������� � �� � ��� �����

������������� ��� ���������� ������������ ���������

����� �� �� � ���� �� ���� ����� ����� ����� � ��

��� � ����� �� �� ����� ��� ��������� � ��� � ��������

�� �� � ��� ��� ��������� �� �������� ������ � ��� ��� � � ��

������ ����� ��� ��������� ��� �� ������ �� ����� ��� �

#�� .���/

���������� ������� �������

���������� �����������

������� ��� �����

������������� ��� ��� ��!

"#��� �!!����$ ���0�� �����������������1

23 $������� 4552

"������ "������������ 46 745548 2366

5295 3::9;54;< �� ����� ������ � 4554 �� ����� ������ =�>� +�� ����� �� ������

?��, 5295 3::975485553: 2

������ ���������;������;������

/ "���� ������ ������� ����, �:9 3 3:9439@A ��%, �:9 3 3:946:B�