A Query Facility for Common Intrusion Detection Framework

Peng Ning,X. Sean Wang,Sushil Jajodia
2000-01-01
Information Systems Security
Abstract: It is essential for intrusion detection systems to shareinformation in order to discover attacks involvingmultiple sites. Common Intrusion Detection Framework(CIDF) is an important step towards enabling differentintrusion detection and response (IDR) components tointeroperate with each other. Although CIDF providesan infrastructure and language support that allows anIDR component to understand the information sent byanother component, it does not contain a facility for acomponent to...
What problem does this paper attempt to address?