da/sec scientific talk on Internet-Security
<!–a href=“https://www.dasec.h-da.de/?attachment_id=3110″>Topic: How to Exchange Security Events? Overview and Evaluation of Formats and Protocols
by Jessica Steinberger
FBI D14/0.13, April 16, 2015 (Thursday), 12.00 noon
Keywords — Exchange formats, exchange protocols, Collaboration, Mitigation
Abstract
Network-based attacks pose a strong threat to the Internet landscape. Recent approaches to mitigate and resolvethese threats focus on cooperation of Internet service providers and their exchange of security event information. A major benefit of a cooperation is that it might counteract a network-based attack at its root and provides the possibility to inform other cooperative partners about the occurrence of anomalous events as a proactive service. This presentation provides a structured overview of existing exchange formats and protocols. We evaluate and compare the exchange formats and protocols in context of high-speed networks. In particular, we focus on flow data. In addition, we investigate the exchange of potentially sensitive data. For our overview, we review different exchange formats and protocols with respect to their use-case scenario, their interoperability with network flow-based data, their scalability in a high-speed network context and develop a classification.