A service model for network security applications
Livio Ricciulli · 2010
We describe a new architecture designed to outsource the complexity of configuring, deploying and operating network security monitoring systems. Our architecture is designed to allow the concurrent operation of best-of-breed network security applications which include flow analysis, Intrusion Detection Systems (IDS), passive Operating System (OS) fingerprinting and application-level service discovery. In addition, we introduce a new framework for the inclusion of network security intelligence data into the security event correlation. We also provide some preliminary quantification of the effectiveness of this new framework.