Meta-IDS' (Meta-Intrusion Detection System) correlates information and alerts from differen't network devices (such as IDS', firewalls, routers, etc.) and display a final result to the analyst in a common format.

At present time, most vendors rely on proprietary formats for their logs, which most other devices annot interpret. At the current time, meta-IDS's can only work by having a separate program which processes the logs into a format which the meta-IDS can understand. In the future, however, meta-IDS' will be easier to implement as vendors add support for a standard format such as the standard that is currently being developed by the Intrusion Dectection Exchange Format Working Group (IDWG).

An eventual goal is to have all IDS products to be able to talk to each other, without the need of a separate program to change the logs into a standard format.

Log in or register to write something here or to contact authors.