The multilateral risks of transformed intrusion through the global network have threatened systems. A regional risk factor influences whole network with the fast speed, but there is no response method which could be processed rapidly. Therefore, an in...
The multilateral risks of transformed intrusion through the global network have threatened systems. A regional risk factor influences whole network with the fast speed, but there is no response method which could be processed rapidly. Therefore, an integrated management system is necessary to collect each risk factor of local area in advance. Analysis of the collected risk information in whole network area should prevent illegal intrusion trials.
This paper utilizes RTSD agent that watches each local network to grasp the present condition of whole network. It detects intrusion risk factor and reports to central IRMS(Intrusion Risk Management System). This IRMS analyzes the intrusion risk statistics of current network and necessary information for response against intrusion, "day-month statistical informations of intrusion type and top 10 lists in graph.
Response of intrusion risk is classified into members and nonmembers. In the case of nonmember, "whois" search server provides the administrator's E-Mail address of intrusion risk system to nonmember. On the other hand, member is offered it by response system of member management database.
In the case of nonmember, the response system transmits only intrusion risk warning mail to nonmember in response. But, in the case of member it sends an warning message and authentication key which can run intrusion interception program automatically to protect the system by refusing service for attacker IP address. Thus, it can keep system safe by fast response against the external intrusion.