A service model for network security applications

Livio Ricciulli · 2010

We describe a new architecture designed to outsource the complexity of configuring, deploying and operating network security monitoring systems. Our architecture is designed to allow the concurrent operation of best-of-breed network security applications which include flow analysis, Intrusion Detection Systems (IDS), passive Operating System (OS) fingerprinting and application-level service discovery. In addition, we introduce a new framework for the inclusion of network security intelligence data into the security event correlation. We also provide some preliminary quantification of the effectiveness of this new framework.

Read the paper · More papers on PaperTik