抽象的な

ATTACK DESCRIPTION LANGUAGE FOR COLLABORATED ALERTS-USING XML AND UML

K.V.S.N. Rama Rao, Manas Ranjan Patra

Statistics of Internet usage are increasing enormously. In harmony, the attacks are also escalating. In the recent era, IDS have gained more popularity in connection to network security. IDS deployed in the network will scan the hosts and the network. It will try to sense misuse detection or anomaly detection. Whenever there is any suspicious activity, IDS will immediately raise alarm. It would be apt to capture the complete description of the new attack as soon as alarm rises. This information to be collected may be heterogeneous because it may be from multiple users, process or hosts. Hence there is a need for common standard language that will work across various domains and platforms. XML is one such language.Writing an XML schema directly would be difficult and inconvenient. The best way to write XML schemas is to useUML models. Hence in this paper, we propose alert collbaration modeling architecture and attack description language using XML notion, which uses UML modeling.