articleJan 1, 2002Closed access

EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances

SRI International

Abstract

The EMERALD (Event Monitoring Enabling Responses to Anomalous Live Disturbances) environment is a distributed scalable tool suite for tracking malicious activity through and across large networks. EMERALD introduces a highly distributed, buildingblock approach to network surveillance, attack isolation, and automated response. It combines models from research in distributed high-volume event-correlation methodologies with over a decade of intrusion detection research and engineering experience. The approach is novel in its use of highly distributed, independently tunable, surveillance and response monitors that are deployable polymorphically at various abstract layers in a large network. These monitors…

Citation impact

710
total citations
FWCI
58.43
Percentile
100%
References
15
Citations per year

Authors

3

Topics & keywords

Keywords
  • Computer science
  • Scalability
  • Event (particle physics)
  • Interoperability
  • Suite
  • Distributed computing
  • The Internet
  • Intrusion detection system
No related works found for this paper.