DS/ISO/IEC 15947
Information technology - Security techniques - IT intrusion detection framework
| Organization: | DS |
| Publication Date: | 21 February 2003 |
| Status: | inactive |
| Page Count: | 31 |
| ICS Code (Information coding): | 35.040 |
scope:
This is a Type 3 Technical Report (TR), which defines a framework for detection of intrusions in IT systems. Many classes of intrusions are considered. These include intrusions that are intentional or unintentional, legal or illegal, harmful or harmless and unauthorized access by insiders or outsiders. The TR focuses on: - establishing common definitions for terms and concepts associated with an IT intrusion detection framework, - describing a generic model of intrusion detection, - providing high level examples of attempts to exploit systems vulnerabilities, - discussing common types of input data and the sources needed for an effective intrusion detection capability, - discussing different methods and combinations of methods of intrusion detection analysis, - describing activities/actions in response to indications of intrusions. This framework explains intrusion detection terms and concepts and describes the reationsip among them. Further, the framework addresses possible ordering of intrusion detection tasks and related activities.
Document History