(Enter summary)
Abstract: This paper presents a hierarchical model
to support attack specification and event abstraction in distributed intrusion detection. The model involves three
concepts: system view, signature, and view definition. A system view provides an abstract interface of a particular
type of information; defined on the instances of system views, a signature specifies certain distributed attacks or
events to be monitored; a view definition is then used to derive information from the matches of a signature... (Update)
Cited by: More
Techniques and Tools for Analyzing Intrusion Alerts - Ning, Cui, Reeves, Xu (2004)
(Correct)
Analyzing Intensive Intrusion Alerts Via Correlation - Peng Ning Yun (2002)
(Correct)
Scoping Security Issues for Interactive Grids - Dwoskin, Basu, Talwar, Kumar, .. (2003)
(Correct)
Similar documents (at the sentence level):
63.6%: Abstraction-Based Intrusion Detection In - Distributed Environments Peng
(Correct)
Active bibliography (related documents): More All
6.9: Abstraction-based Intrusion Detection in Distributed.. - Ning, Jajodia, Wang (2001)
(Correct)
1.3: Intrusion Detection: A Bibliography - Mé, Michel (2001)
(Correct)
1.0: Modeling Requests among Cooperating Intrusion Detection Systems - Ning, Wang, Jajodia (2000)
(Correct)
Similar documents based on text: More All
0.6: Correlating Alerts Using Prerequisites of Intrusions - Ning, Reeves, Cui (2001)
(Correct)
0.5: Cards: A Distributed System For Detecting Coordinated Attacks - Yang, Ning, Wang, Jajodia (2000)
(Correct)
0.3: Information Leakage from Optical Emanations - Loughry, Umphress (2002)
(Correct)
Related documents from co-citation: More All
6: LAMBDA: A Language to Model a Database for Detection of Attacks (context) - Cuppens, Ortalo
6: requireprovide model computer attack
- Templeton, requires et al. - 2000
5: Abstraction-based misuse detection: High-level specications and adaptable strate..
- Lin, Wang et al. - 1998
BibTeX entry: (Update)
P. Ning, S. Jajodia, and X. S. Wang. Abstraction-based intrusion detection in distributed environments. Information and System Security, 4(4):407--452, 2001. http://citeseer.ist.psu.edu/article/ning01abstractionbased.html More
@article{ ning01abstractionbased,
author = "Peng Ning and Sushil Jajodia and Xiaoyang Sean Wang",
title = "Abstraction-based intrusion detection in distributed environments",
journal = "Information and System Security",
volume = "4",
number = "4",
pages = "407-452",
year = "2001",
url = "citeseer.ist.psu.edu/article/ning01abstractionbased.html" }
Citations (may not include all citations):
1044
Maintaining knowledge about temporal intervals (context) - Allen - 1983
162
Implementation techniques for main memory database systems (context) - DeWitt, Katz et al. - 1984
132
EMERALD: Event monitoring enabling response to anomalous liv..
- Porras, Neumann - 1997
121
Network intrusion detection (context) - Mukherjee, Heberlein et al. - 1994
105
State transition analysis: A rule-based intrusion detection ..
- Ilgun, Kemmerer et al. - 1995
99
Temporal reasoning based on semi-intervals
- Freksa - 1992
79
Computer security threat monitoring and surveillance (context) - Anderson - 1980
78
Analysis of a denial of service attack on TCP
- Schuba, Krsul et al.
70
A data mining framework for building intrusion detection mod..
- Lee, Stolfo et al.
62
The NIDES statistical component: Description and justificati.. (context) - Javits, Valdes - 1993
59
USTAT: A real-time intrusion detection system for UNIX
- Ilgun - 1993
58
A pattern matching model for misuse intrusion detection
- Kumar, Spafford - 1994
50
NetSTAT: A network-based intrusion detection system
- Vigna, Kemmerer - 1999
48
Classification and Detection of Computer Intrusions
- Kumar - 1995
43
NADIR: An automated system for detecting network intrusion a.. (context) - Hochberg, Jackson et al. - 1993
42
A First Course in Database Systems (context) - Ullman, Widom - 1997
39
Detecting computer and network misuse through the production..
- Lindqvist, Porras
38
Cooperating security managers: A peer-based intrusion detect.. (context) - White, Fisch et al. - 1996
38
Haystack: An intrusion detection system (context) - Smaha - 1988
35
A database of computer attacks for the evaluation of intrusi..
- Kendall - 1999
34
NetSTAT: A network-based intrusion detection approach
- Vigna, Kermmerer - 1998
22
Abstraction-based misuse detection: High-level specification..
- Lin, Wang et al. - 1998
22
Abstraction-Based Misuse Detection: High-level Specification..
- Lin - 1998
22
Intrusion detection using autonomous agents (context) - Spafford, Zamboni - 2000
21
distributed intrusion detection system) - motivation (context) - Snapp, Brentano et al. - 1991
21
The blocks extensible exchange protocol core (context) - Rose - 2001
20
Languages and Tools for Rule-Based Distributed Intrusion Det.. (context) - Mounji - 1997
18
Intrusion detection message exchange format data model and e.. (context) - Curry, Debar - 2001
17
Design and implementation of a scalable intrusion detection ..
- Jou, Gong et al. - 2000
16
Network Intrusion Detection: An Analyst's Handbook (context) - Northcutt - 1999
15
A common intrusion detection framework (context) - Kahn, Porras et al. - 1998
14
NSTAT: A model-based real-time network intrusion detection s..
- Kemmerer - 1997
12
Security and privacy for partial order time
- Tygar - 1994
11
Deciduous: Decentralized source identification for network-b.. (context) - Chang, Narayan et al. - 1999
10
A framework for cooperative intrusion detection
- Frincke, Tobin et al. - 1998
9
A data mining and CIDF based approach for detecting novel an..
- Lee, Nimbalkar et al. - 2000
9
JiNao: Design and implementation of a scalable intrusion det..
- Wu, Chang et al.
9
Macmillan Technology Publishing (context) - Bace - 2000
8
Holding intruders accountable on the internet
- Staniford-Chen, Heberlein
8
Detecting novel network intrusion using bayes estimators (context) - Barbara, Wu et al. - 2001
7
A common intrusion specification language (context) - Feiertag, Kahn et al. - 2000
7
CARDS: A distributed system for detecting coordinated attack..
- Yang, Ning et al. - 2000
7
The common intrusion detection framework architecture (context) - Porras, Schnackenberg et al. - 1998
7
GrIDS - a graph based intrusion detection system for large n..
- Staniford-Chen, Cheung et al. - 1996
7
Intrusion detection inter-component adaptive negotiation
- Feiertag, Rho et al. - 2000
7
A security analysis of the NTP protocol version (context) - Bishop - 1990
6
Internetwork security monitor: An intrusion-detection system.. (context) - Heberlein, Mukherjee et al. - 1992
6
Using embedded sensors for detecting network attacks
- Kerschbaum, Spafford et al. - 2000
5
Communication in the common intrusion detection framework (context) - Kahn, Bolinger et al. - 1998
5
and intrusion detection (context) - Ho, Frincke et al. - 1998
4
Modeling requests among cooperating intrusion detection syst..
- Ning, Wang et al. - 2000
3
Architecture for real-time data management: Timesten's core .. (context) - Software - 2001
3
A query facility for common intrusion detection framework
- Ning, Wang et al. - 2000
2
Internet Draft draft-ietf-idwg-beep-tunnel (context) - New, profile - 2001
2
Towards tracing hidden attackers on untrusted IP networks (context) - Chang, Wu et al. - 2000
2
Internet Draft draft-ietf-idwg-beep-idxp (context) - Feinstein, Matthews et al. - 2001
2
Distibuted audit trail analysis (context) - Mounji, Charlier et al. - 1995
2
Webster's New World Dictionary of Amercian English (context) - Neufeldt - 1988
The graph only includes citing articles where the year of publication is known.
Documents on the same site (http://www.csc.ncsu.edu/faculty/ning/vitae.html): More
Discovering Calendar-based Temporal Association Rules - Li, Ning, Wang, Jajodia (2001)
(Correct)
An Algebraic Representation of Calendars - Ning, Wang, Jajodia (2001)
(Correct)
Avoiding Loss of Fairness Owing to Failures in Fair Data.. - Liu, Ning, Jajodia
(Correct)
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC