The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances

Author

Phillip A. Porras,Peter G. Neumann

Entry type

techreport

Abstract

This paper summarizes the EMERALD (Event Monioring Enabling Responses to Anomalous Live Disturbances) environment, a distributed scalable tool suite for tracking malicious activity through and across large networks. EMERALD introduces a highly distributed, building-block approach to network surveillance, attack isolation, and automated response. It combines models from research in distributed high-volume event-correlation methodologies with over a decade worth of intrusion-detection research and engineering experience. The approach is novel in its use of highly distributed, independently tunable, surveillance and response monitors that are deployable polymorphically at various abstract layers in a large network. These monitors demonstrate a streamlined intrusion-detection design that combines signature-analysis with statistical profiling to provide localized real-time protection of the most widely used network services on the Internet. Equally important, EMERALD introduces a recursive framework for coordinating the dissemination of analyses from the distributed monitors to provide a global detection and response capability to counter attacks occurring across and entire network enterprise. Further, EMERALD introduces a versatile application programmers' interface that enhances its ability to integrate with the target hosts and provides a high degree of interoperability with third-party tool suites.

Address

Menlo Park, CA 94025

Institution

SRI International

Key alpha

Porras

Pages

1 - 16

Publication Date

2001-01-01

Keywords

intrusion detection, anomaly detection, misuse detection, network security,,coordinated attacks, information warfare, system survivability

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.