Back to search

North Carolina State University

Data Organization and Abstraction for Distributed Intrusion Detection

Abstract

dc:description.abstract

Due to the rapid pace of technological development, we find that old systems are 'thrown away' in favor of newer technology. However, we find that data created by these earlier systems is persistent. A Digital Rosetta Stone [16] must be created to allow newer systems to correctly process data created by earlier technology. This document provides a case study of techniques that can be used to create a Digital Rosetta Stone between data formats and within a single evolving format. The intrusion detection domain provides a solid basis for this study. In a distributed intrusion detection system, many sensors and analyzers must communicate with each other. The Intrusion Detection Message Exchange Format (IDMEF) is a standardized XML format for such communication. To its detriment, the IDMEF specification has been evolving since its inception. Also, the XML parsing during queries can be cumbersome and hinder intrusion detection. Therefore, two Digital Rosetta Stones were created. One migrates information between different versions of the IDMEF standard. The other translates IDMEF XML information into a relational database management system to improve query performance.

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • McBride, Sean Patrick
Advisors dc:contributor.advisor
  • Dr. Christopher G. Healey, Committee Member
  • Dr. Robert St. Amant, Committee Chair
  • Dr. Laurie Williams, Committee Member

Subjects

dc:subject × 2

Rights

dc:rights
Statement dc:rights
  • I hereby certify that, if appropriate, I have obtained and attached hereto a written permission statement from the owner(s) of each third party copyrighted matter to be included in my thesis, dissertation, or project report, allowing distribution as specified below. I certify that the version I submitted is the same as that approved by my advisory committee. I hereby grant to NC State University or its agents the non-exclusive license to archive and make accessible, under the conditions specified below, my thesis, dissertation, or project report in whole or in part in all forms of media, now or hereafter known. I retain all other ownership rights to the copyright of the thesis, dissertation or project report. I also retain the right to use in future works (such as articles or books) all or part of this thesis, dissertation, or project report.

Identifiers

dc:identifier.*
Dc Identifier Other
etd-04052005-182228

Chain of custody

source
Harvested from
North Carolina State University
Base URL
repository.lib.ncsu.edu/server/oai/request
Last updated
2026-08-21
Source record
OAI-PMH GetRecord
citation

McBride, Sean Patrick. Data Organization and Abstraction for Distributed Intrusion Detection. 2005. http://www.lib.ncsu.edu/resolver/1840.16/1061