intrusion detection
Click on the red underlined text to get to the source
...
This document defines requirements for the Intrusion Detection
Message Exchange Format (IDMEF) [5], a product of the Intrusion
Detection Exchange Format Working Group ...
... Intrusion Detection
Message Exchange Format (IDMEF) [5], a product of the Intrusion
Detection Exchange Format Working Group (IDWG). IDMEF was planned to
...
... IDWG). IDMEF was planned to
be a standard format that automated Intrusion Detection Systems
(IDSs) [4 ...
... The reasons such a format should be useful are as follows:
1. A number of commercial and free Intrusion Detection Systems are
available and more are becoming available all the time. Some
products are aimed at detecting intrusions on the network ...
... 3. The existence of a common format should allow components from
different IDSs to be integrated more readily. Thus, Intrusion
Detection (ID) research should migrate into commercial products
more easily.
...
... Intrusion Detection Terms ...
...
The raw information that an intrusion detection system uses to detect
unauthorized or undesired activity. Common data sources include (but
are not limited to) raw network ...
...
Intrusion detection system. Some combination of one or more of the
following components: sensor, analyzer, manager.
...
...
Since network security and intrusion detection are areas that cross
geographic, political, and cultural boundaries, the IDMEF messages
...
... deviations from the established baseline. Each of these IDSs reports
different data that, in part, depends on their intrusion detection
methodology. All MUST be supported by this standard.
...
...
As intrusion detection technology continues to evolve, it is likely
that additional information relating to detected events will become
available. The IDMEF ...
... Debar, H., Curry, D., and B. Feinstein, "The Intrusion Detection Message Exchange Format (IDMEF)", RFC 4765exp, March 2007. ...
