Home     Top: Security: Intrusion Detection    [Access Control   Encryption   Information Warfare   Intellectual Property Protection   Intrusion Detection]

Change ordering:   Authority   Hubs (tutorials)   Date   Expected authority       Show titles only
Reverse date order

This directory is created automatically and some papers may be mislabeled. Only document within the CiteSeer database are listed. The directory is intended to provide entry points for browsing the database and is not intended to be authoritative. Papers may not appear in all relevant categories. For example, papers in a sub-category may not appear in higher level categories.

PowerNP Network Processor: Hardware, Software And Applications - Allen, Bass, Basso, Boivie.. (2003)   (Correct)
Deep packet processing is migrating to the edges of service provider networks to simplify and speed up core functions. On the other hand, the cores of such networks are migrating to the switching of h... /

A Virtual Machine Introspection Based Architecture for Intrusion.. - Garfinkel, Rosenblum (2003)   (Correct)
Today's architectures for intrusion detection force the IDS designer to make a difficult choice. If the IDS resides on the host, it has an excellent view of what is happening in that host's software, ... /

Traps and Pitfalls: Practical Problems in System Call Interposition.. - Garfinkel (2003)   (Correct)
System call interposition is a powerful method for regulating and monitoring application behavior. In recent years, a wide variety of security tools have been developed that use this technique. This a... /

Indexing Weighted-Sequences in Large Databases - Wang, Perng, Fan, Park, Yu (2003)   (Correct)
We present an index structure for managing weightedsequences in large databases. A weighted-sequence is defined as a two-dimensional structure where each element in the sequence is associated with a w... / database management network intrusion detection etc. Recently the field

Shielding RBAC Infrastructures from Cyberterrorism - Belokosztolszki, Eyers (2003)   (Correct)
OASIS is a distributed RBAC implementation with many extensions. Sound policy design will permit OASIS to protect the distributed resources whose access privileges it controls. However, through operat... / control OASIS security intrusion detection . Introduction Few

IBM PowerNP network processor: Hardware, software, and applications - Allen, Bass, Basso, Boivie.. (2003)   (Correct)
This paper provides an overview of the IBM PowerNP TM NP4GS3 network processor and how it addresses these issues. Its hardware and software design characteristics and its comprehensive base operatin... / firewalling and intrusion detection Large investments

Indra: A peer-to-peer approach to network intrusion detection and.. - Janakiraman, Waldvogel, Zhang (2003)   (Correct)
While the spread of the Internet has made the network ubiquitous, it has also rendered networked systems vulnerable to malicious attacks orchestrated from anywhere. These attacks or intrusions typical... / approach to network intrusion detection and prevention br I. INTRODUCTION A. Intrusion Detection Systems Intrusion is the

Adaptive Security for Multi-layer Ad-hoc Networks - Kong, Luo, Xu, Gu, Gerla, Lu (2002)   (Correct)
Secure communication is critical in military environments where the network infrastructure is vulnerable to various attacks and compromises. A conventional centralized solution breaks down when the se... /

A Group Membership Protocol For An Intrusion-Tolerant Group.. - Ramasamy (2002)   (Correct)
Group Communication Systems have been developed to address the problem of maintaining consistency of replicated information. This thesis describes the research work that resulted in the design, develo... / middleware large-scale intrusion detection systems dependable trusted

A Security Architecture for Application Session Handoff - Skow, Kong, Phan, Cheng, Guy.. (2002)   (Correct)
Ubiquitous computing across a variety of wired and wireless connections still lacks an effective security architecture. In our research work, we address the specific issue of designing and building a ... /

Quantifying the Cost of Providing Intrusion Tolerance in Group.. - Ramasamy, Pandey, Lyons, Cukier.. (2002)   (Correct)
Group communication systems that provide consistent group membership and reliable, ordered multicast properties in the presence of faults resulting from malicious intrusions have not been analyzed ext... /

Current State of Data Mining - Drewry, Gu, Hocking, Kang, Schutt.. (2002)   (Correct)
This report is a compendium of results uncovered in CS 851, spring semester 2002. unknown Current State of Data Mining Darren T. Drewry, Lin Gu, A. Benjamin Hocking, Kyoung-Don Kang, Robert C. Schut... /

Distributed Pattern Detection for Intrusion Detection - Krügel, Toth (2002)   (Correct)
Evidence of attacks against a network and its resources is often scattered over several hosts. Intrusion detection systems therefore have to collect and correlate information from different sources. F... / Pattern Detection for Intrusion Detection Christopher Krugel br scattered over several hosts. Intrusion detection systems therefore have to

Parzen-Window Network Intrusion Detectors - Calvin (2002)   (Correct)
Network intrusion detection is the problem of detecting anomalous network connections caused by intrusive activities. Many intrusion detection systems proposed before use both normal and intrusion dat... /

A Recursive Session Token Protocol For Use in Computer Forensics and.. - Clay (2002)   (Correct)
We introduce a new protocol designed to assist in the forensic investigation of malicious network-based activity, specifically addressing the stepping-stone scenario in which an attacker uses a chain ... / was intended to perform an intrusion detection function so that br use by network gateways and Intrusion Detection Systems IDS When the IP

Windows Performance Monitoring and Data Reduction - Using Watchtower Michael (2002)   (Correct)
We describe and evaluate WatchTower, a set of library routines that simplifies the collection of performance data for the monitoring of Windows NT/2000. WatchTower has an overhead similar to that of e... /

QoS-Driven Server Migration for Internet Data Centers - Ranjan, Rolia, Fu, Knightly (2002)   (Correct)
Many organizations have chosen to host Internet applications at Internet Data Centers (IDCs) located near network access points of the Internet to take advantage of their high availability, large netw... /

The Role of Event Description in Architecting Dependable Systems - Dias, al. (2002)   (Correct)
Software monitoring is a well-suited technique to support the development of dependable systems, and has been widely applied not only for this purpose, but also for others such as debugging, security,... /

Ensemble Learning for Intrusion Detection in - Luca (2002)   (Correct)
The security of computer networks plays a strategic role in modern computer systems. In order to enforce high protection levels against threats, a number of software tools are currently developed. Int... /

Complete Expression Trees for Evolving Fuzzy Classifier Systems with.. - Gomez, Dasgupta, Nasaroui, Gonzalez (2002)   (Correct)
We propose a new linear representation scheme for evolving fuzzy rules using the concept of complete binary tree structures. We also use special genetic operators such as gene addition, gene deletio... /

A Component-Based Event-Driven Interactive Visualization Software.. - Erbacher (2002)   (Correct)
This paper describes our research to develop an effective visualization environment for real-time intrusion detection and the resultant architecture. The environment requirements necessitate that effe... / environment for real-time intrusion detection and the resultant br architecture for our intrusion detection environment This

Privilege Flows Modeling for Effective Intrusion Detection based on.. - Park, Cho (2002)   (Correct)
An intrusion detection system utilizes various statistical information scattered around within the system. It can abstract information from the normal behaviors of a system and detect attacks regard... /

Specialized Hardware for Deep Network Packet Filtering - Cho, Navab, Mangione-Smith (2002)   (Correct)
Many computer network provide limited security through simple firewall feature in router and switch. Some networks that require higher security use deep packet filter to capture packets that can not... /

InfoSpect: Using a Logic Language for System Health Monitoring in.. - Roscoe, Mortier, Jardetzky, Hand (2002)   (Correct)
Dependable systems cannot be built without a monitoring and management component. In this paper we propose using a wide variety of information gathering tools coupled with custom scripts and a Prolog ... / by for example networking intrusion detection systems. Instead we focus

Stateful Intrusion Detection for High-Speed Networks - Kruegel, Valeur, Vigna, Kemmerer (2002)   (Correct)
As networks become faster there is an emerging need for security analysis techniques that can keep up with the increased network throughput. Existing network-based intrusion detection sensors can bare... /

SINS: A Middleware for Autonomous Agents and Secure - Code Mobility In (2002)   (Correct)
Ramesh Bharadwaj Center for High Assurance Computer Systems Naval Research Laboratory Washington, DC, 20375-5320 USA ramesh@itd.nrl.navy.mil 1. unknown SINS: A Middleware for Autonomous Agents a... /

When Ants Attack: Security Issues for Stigmergic Systems - Weilin Zhong And (2002)   (Correct)
Stigmergic systems solve global problems by using indirect communication mediated by an environment. Because they are localized and dynamic, stigmergic systems are self-organizing, robust and adaptive... / White distributed intrusion detection and response Fenet br Hassas. A distributed Intrusion Detection and Res onse System

Mimicry Attacks on Host-Based Intrusion Detection Systems - Wagner, Soto (2002)   (Correct)
We examine several host-based anomaly detection systems and study their security against evasion attacks. First, we introduce the notion of a mimicry attack, which allows a sophisticated attacker to c... / Mimicry Attacks on Host-Based Intrusion Detection Systems David br call for further research on intrusion detection from both attacker's and

Denial of Service in Sensor Networks - Wood, Stankovic (2002)   (Correct)
Unless their developers take security into account at design time, sensor networks and the protocols they depend on will remain vulnerable to denial of service attacks. We identify denial of service w... /

An Immunogenetic Technique to Detect Anomalies in Network Traffic - Gonzalez, Dasgupta (2002)   (Correct)
The paper describes an immunogenetic approach which can detect a wide variety of intrusive activities on networked computers. In particular, this technique is inspired by the negative selection me... /

Rule-Based Anomaly Pattern Detection for Detecting Disease Outbreaks - Wong, Moore, Cooper, Wagner (2002)   (Correct)
This paper presents an algorithm for performing early detection of disease outbreaks by searching a database of emergency department cases for anomalous patterns. unknown Rule-Based Anomaly Pattern ... /

Towards an Artificial Immune System for Network Intrusion Detection: - An Investigation Of (2002)   (Correct)
One significant feature of artificial immune systems is their ability to adapt to continuously changing environments, dynamically learning the fluid patterns of `self' and predicting new patterns o... /

Secure Audit Logging with Tamper-Resistant Hardware - Chong, Peng, Hartel (2002)   (Correct)
Secure perimeter schemes (e.g. DRM) and tracing traitor schemes (e.g. watermarking, audit logging) strive to mitigate the problems of content escaping the control of the rights holder. Secure audit lo... /

Bootstrapping Security Associations for Routing in Mobile Ad-Hoc.. - Bobba, Eschenauer, Gligor, Arbaugh (2002)   (Correct)
To date, most solutions proposed for secure routing in mobile, ad-hoc networks (MANETs) assume that secure associations between pairs of nodes can be established on-line unknown Created on 5/31/2002 1... / Other protocols rely on intrusion-detection mechanisms to discover and br and tacitly assume that the intrusion-detection sensors running in network

Report on a Working Session on Security in Wireless Ad Hoc Networks - Buttyán, Hubaux (2002)   (Correct)
Most proposed routing protocols for mobile ad hoc networks are vulnerable to modification, impersonation and fabrication attacks. The proposed secure rout8 Mobile Computing and Communications Review,... / Secure routing and intrusion detection. Existing ad hoc routing br focused on the problem of intrusion detection in ad hoc networks.

LicenseScript - A Language and Framework for Calculating Licenses on.. - Chong, Law, Etalle, Hartel (2002)   (Correct)
The project LicenseScript develops and demonstrates an integrated framework for analysis and design of secure information delivery systems. The contributions of this project are the demonstration of n... /

Flux: An Adaptive Partitioning Operator for Continuous Query Systems - Shah, Hellerstein, Chandrasekaran.. (2002)   (Correct)
The long-running nature of continuous queries poses new scalability challenges for dataflow processing. CQ systems execute pipelined dataflows that may be shared across multiple queries. The scalabili... /

Connection-history based anomaly detection - Toth, Krügel (2002)   (Correct)
this paper, we present an approach to automatically identify worms and perform damage limitation by rewall rule modi cation unknown Proceedings of the 2002 IEEE Workshop on Information Assurance an... /

Intrusion Detection, Diagnosis, and Recovery with Self-Securing.. - Strunk, Goodson, Pennington, Soules, .. (2002)   (Correct)
Self-securing storage turns storage devices into active parts of an intrusion survival strategy. From behind a thin storage interface (e.g., SCSI or CIFS), a self-securing storage sen,er can watch sto... /

Self-Securing Network Interfaces: What, Why and How - Ganger, Economou, Bielski (2002)   (Correct)
Self-securing network interfaces (NIs) examine the packets that they move between network links and host software, looking for and potentially blocking malicious network activity. This paper describes... /

Metadata Efficiency in a Comprehensive Versioning File System - Soules, Goodson, Strunk, Ganger (2002)   (Correct)
A comprehensive versioning file system creates and retains a new file version for every WRITE or other modification request. The resulting history of file modifications provides a detailed view to too... /

Using CSP to detect Insertion and Evasion Possibilities within the.. - Rohrmair, Lowe (2002)   (Correct)
In this paper we will demonstrate how one can model and analyse Intrusion Detection Systems (IDSs) and their environment using the process algebra Communicating Sequential Processes (CSP) [11, 21] a... / Possibilities within the Intrusion Detection Area Gordon Thomas br one can model and analyse Intrusion Detection Systems IDSs and their

What do we mean by Network Denial of Service? - Shields (2002)   (Correct)
Recent network denial-of-service attacks have brought about awareness of the vulnerability of increasingly important network services. While denial of service is not a new problem, and some of the net... / of methods of foiling intrusion detection systems. They cite a br of Service Using Cooperative Intrusion Detection in Proceedings of the

Current approaches to detecting intrusions - Gonzalez (2002)   (Correct)
Before the flourishing of the Internet, computers were limited to the walls of the organization where computers were linked to each other but had little contact with computer systems outside. Now, we ... / with the implementation of Intrusion Detection Systems IDS and Incident br Strategies. However existent intrusion detection systems are generally

A Practical Approach to Solve Secure Multi-Party Computation Problems - Du, Zhan (2002)   (Correct)
Secure Multi-party Computation (SMC) problems deal with the following situation: Two (or many) parties want to jointly perform a computation. Each party needs to contribute its private input to this c... /

Intrusion Detection: A Bibliography - Mé, Michel (2001)   (Correct)
This document contains more than 600 references, dated from 1980 to 2001. We undoubtedly have forgotten some important citations, either through oversight or ignorance. Moreover, errors may remain in ... / Intrusion Detection A Bibliography Ludovic br references relating to intrusion detection. Intrusion detection is

Automated Discovery of Concise Predictive Rules for Intrusion.. - Helmer, Wong, Honavar, Miller (2001)   (Correct)
This paper details an essential component of a multi-agent distributed knowledge network system for intrusion detection. We describe a distributed intrusion detection architecture, complete with a dat... / Concise Predictive Rules for Intrusion Detection Guy Helmer Johnny br knowledge network system for intrusion detection. We describe a distributed

Intrusion Detection via Static Analysis - Wagner, Dean (2001)   (Correct)
One of the primary challenges in intrusion detection is modelling typical application behavior, so that we can recognize attacks by their atypical effects without raising too many false alarms. We sho... / Intrusion Detection via Static Analysis David br of the primary challenges in intrusion detection is modelling typical

Fault Tolerance in Critical Information Systems - Elder (2001)   (Correct)
Critical infrastructure applications provide services upon which society depends heavily; such applications require constant, dependable operation in the face of various failures, natural disasters, a... / Figure Money-center bank intrusion detection alarm on event br Experiment Branch bank intrusion detection alarms

Using Internal Sensors For Computer Intrusion Detection - Zamboni (2001)   (Correct)
xiv 1 unknown USING INTERNAL SENSORS FOR COMPUTER INTRUSION DETECTION Submitted to the Faculty of Purdue University by Diego Zamboni CERIAS TR 2001-42 Center for Education and Research in Info... /

Information-Theoretic Measures for Anomaly Detection - Lee, Xiang (2001)   (Correct)
Anomaly detection is an essential component of the protection mechanisms against novel attacks. In this paper, we propose to use several information-theoretic measures, namely, entropy, conditional en... / measures. Introduction Intrusion detection systems IDSs is an br The two main techniques for intrusion detection ID are misuse detection

Denial of service in public key protocols - Eronen (2001)   (Correct)
Network denial of service attacks have become a widespread problem on the Internet. However, denial of service is often considered to be an implementation issue by protocol designers. In this paper I ... / by spoofed IP addresses. Intrusion detection and reaction systems aim to br or few IP addresses. To an intrusion detection system this might look like

Software Fault Tree and Colored Petri Net Based Specification, Design .. - Helmer, Wong, Slagell, Honavar.. (2001)   (Correct)
Colored Petri Nets (CPNs) are examined for use as a design specication for an Intrusion Detection System (IDS). Hierarchical CPNs are created to detect critical stages of intrusions. Two examples of... / Implementation of Agent-Based Intrusion Detection Systems Guy Helmer br a design specication for an Intrusion Detection System IDS Hierarchical

Security in Dynamic Execution Environments - Inoue (2001)   (Correct)
Trends in computer architecture and in language design and implementation are resulting in dynamic execution environments. A program's environment is the interface and implementation of the system hos... / . Application Specific Intrusion Detection . br required for optimization. Intrusion detection and optimization both rely

An Environment for Security Protocol Intrusion Detection - Yasinsac (2001)   (Correct)
Secure electronic communication relies on cryptography. Even with perfect encryption, communication may be compromised without effective security protocols for key exchange, authentication, etc. We a... / for Security Protocol Intrusion Detection Alec Yasinsac br method is based on classic intrusion detection techniques of

A glimpse into the future of ID - Bass, Gruber (2001)   (Correct)
Cyberspace is a complex dimension of both enabling and inhibiting data flows in electronic data networks. Current generation intrusion detection (ID) systems are not technologically advanced enough to... / networks. Current-generation intrusion-detection systems IDSes are not br Control ITC and future intrusion-detection systems. Of course this

SAVE: Source Address Validity Enforcement Protocol - Li, Mirkovic, Wang, Reiher, Zhang (2001)   (Correct)
Many network attacks forge the source address in their IP packets to block traceback. Recently, research activity has focused on packet-tracing mechanisms to counter this deception. Unfortunately, the... / sources of an attack. Intrusion detection and network problem br is possible. Network intrusion detection has also studied how to

A Hybrid Approach to the Profile Creation and Intrusion Detection - Marin, Ragsdale, Surdu (2001)   (Correct)
Anomaly detection involves characterizing the behaviors of individuals or systems and recognizing behavior that is outside the norm. This paper describes some preliminary results concerning the robust... / to the Profile Creation and Intrusion Detection Jack Marin Daniel br set. . Introduction Intrusion detection may be defined as the

A Hybrid Approach to Profile Creation and Intrusion Detection - Marin, Ragsdale, Surdu (2001)   (Correct)
Anomaly detection involves characterizing the behaviors of individuals or systems and recognizing behavior that is outside the norm. This paper describes some preliminary results concerning the robust... / to Profile Creation and Intrusion Detection John A. Marin Daniel br set. . Introduction Intrusion detection may be defined as the

Middleware Support for Voting and Data Fusion - Zhiyuan (2001)   (Correct)
Middleware is a class of software systems above the operating system which is becoming widely used for programming distributed systems. Voting is a fundamental operation when distributed systems invol... / increasingly prevalent and intrusion detection systems which are br to support features such as intrusion detection. . Basic Voter

Proactive Detection of Distributed Denial of Service Attacks using.. - Cabrera, Lewis, Qin, Lee, Prasanth.. (2001)   (Correct)
In this paper we propose a methodology for utilizing Network Management Systems for the early detection of Distributed Denial of Service (DDoS) Attacks. Although there are quite a large number of even... / related to the area of Intrusion Detection eg. Our br System could be used for Intrusion Detection. In the present effort we

Agile Monitoring for Cyber Defense - Doyle, Kohane, Long, Shrobe.. (2001)   (Correct)
The Monitoring, Analysis, and Interpretation Tool Arsenal (MAITA) seeks to support rapid construction and empirical reconfiguration of cyber defense monitoring systems inside the opponent decision cyc... / elements such as existing intrusion detection systems and sensors in a br alerting models in the intrusion detection literature. In the

Outlier Detection for High Dimensional Data - Aggarwal, Yu (2001)   (Correct)
The outlier detection problem has important applications in the field of fraud detection, network robustness analysis, and intrusion detection. Most such applications are high dimensional domains in w... / robustness analysis and intrusion detection. Most such applications are br credit card fraud network intrusion detection financial applications and

Log Auditing through Model-Checking - Roger, Goubault-Larrecq (2001)   (Correct)
Log auditing is a basic intrusion detection mechanism, whereby attacks are detected by uncovering matches of sequences of events against signatures. We argue that this problem is naturally expressed a... / Log auditing is a basic intrusion detection mechanism whereby attacks br it is a cornerstone of intrusion detection which relies on

Windows Performance Monitoring and Data Reduction using WatchTower.. - Knop, al. (2001)   (Correct)
Michael W. Knop Praveen K. Paritosh Peter A. Dinda Jennifer M. Schopf fknop, paritosh, pdinda, jmsg@cs.northwestern.edu Department of Computer Science Northwestern University 1890 Maple Avenue Ev... / user profiling intrusion detection and br S.And Somayaji A. Intrusion Detection Using Sequences Of System

Mining Needles in a Haystack: Classifying Rare Classes via Two-Phase.. - Joshi, Agarwal (2001)   (Correct)
Learning models to classify rarely occurring target classes is an important problem with applications in network intrusion detection, fraud detection, or deviation detection in general. In this paper,... / with applications in network intrusion detection fraud detection or br real-life network intrusion detection dataset. Our method is

Learning Visual Models of Social Engagement - Singletary, Starner (2001)   (Correct)
We introduce a face detector for wearable computers that exploits constraints in face scale and orientation imposed by the proximity of participants in near social interactions. Using this method we d... / may be disrupted by the intrusion. Detection of social engagement allows

Best Practices for Secure Development - Peteanu (2001)   (Correct)
this document: http://members.rogers.com/razvan.peteanu -2- Revision History Version Release Date Notes 4.03 October 12, 2001 fixed a few other typos 4.02 October 11, 2001 added a missing reference ... /

Enhancing Survivability of Security Services using Redundancy - Hiltunen, Schlichting, Ugarte (2001)   (Correct)
Traditional distributed system services that provide guarantees related to confidentiality, integrity, and authenticity enhance security, but are not survivable since each attribute is implemented by ... / key. Similarly an intrusion detection system IDS can be viewed br it upon function call return. Intrusion detection in general augments a

A Scalable Algorithm for Clustering Sequential Data - Valerie Guralnik George (2001)   (Correct)
Many scientific and commercial domains have seen an enormous growth of data in recentyears. Such data sets have inherent sequential nature. The clustering of such data is useful for various purposes.... / retail transactions intrusion detection and web-logs have an

A Building Block Approach to Intrusion Detection - Crosbie, Kuperman (2001)   (Correct)
This paper details the design and implementation of a host-based intrusion detection system (Hewlett-Packard's Praesidium IDS/9000) and a specialized kernel data source which supplies customized data ... /

Forward-Secure Signatures with Optimal Signing and Verifying - Itkis, Reyzin (2001)   (Correct)
We propose the rst forward-secure signature scheme for unknown Forward-Secure Signatures with Optimal Signing and Verifying Gene Itkis and Leonid Reyzin Boston University Computer Science Dept.... / of the old keys and proper intrusion detection are non-trivial tasks. br perform such deletion and intrusion detection certainly more reasonable

Trust Relationships in a Mobile Agent System - Tan, Moreau (2001)   (Correct)
The notion of trust is presented as an important component in a security infrastructure for mobile agents. A trust model that can be used in tackling the aspect of protecting mobile agents from ho... /

Event Recognition Beyond Signature and Anomaly - Doyle, Kohane, Long, Shrobe.. (2001)   (Correct)
Notions of signature and anomaly have formed the basis of useful methods in cyber defense, but even in combination provide only weak evidence for recognizing many events of interest. One can recogni... / of current methods for intrusion detection and cyber defense. br - side the lab. Intrusion detection systems report observing

Designing a Web of Highly-Configurable Intrusion Detection Sensors - Vigna, Kemmerer, Blix (2001)   (Correct)
Intrusion detection relies on the information provided by a number of sensors deployed throughout the monitored network infrastructure. Sensors provide information at different abstraction levels and ... / a Web of Highly-Con gurable Intrusion Detection Sensors Giovanni Vigna br Abstract. Intrusion detection relies on the information

The Willow Architecture: Comprehensive Survivability for Large-Scale.. - Knight, Heimbigner, Wolf, Carzaniga, .. (2001)   (Correct)
The Willow architecture is a comprehensive approach to survivability in critical distributed applications. Survivability is achieved in a deployed system using a unique combination of (a) fault avoi... /

Building a Robust Software-Based Router Using Network Processors - Spalink, Karlin, Peterson, Gottlieb (2001)   (Correct)
Recent efforts to add new services to the Internet have increased interest in software-based routers that are easy to extend and evolve. This paper describes our experiences using emerging network pro... / support-e.g.firewalls intrusion detection proxies level-n br performance monitoring intrusion detection application-level

Mining The Top-K Frequent Itemset With Minimum Length M - Cong (2001)   (Correct)
With the explosive growth of data stored in electronic form, data mining has become essential in searching nontrivial, implicit, previously unknown and potentially useful information from a huge amo... / census data and even network intrusion detection. Association rule mining

Symbiotic Interfaces For Wearable Face Recognition - Singletary, Starner (2001)   (Correct)
We introduce a wearable face detection method that exploits constraints in face scale and orientation imposed by the proximity of participants in near social interactions. Using this method we describ... / may be disrupted by the intrusion. Detection of social engagement allows

Characteristics of Network Traffic Flow Anomalies - Paul Barford And (2001)   (Correct)
INTRODUCTION One of the primary tasks of network administrators is monitoring routers and switches for anomalous traffic behavior such as outages, configuration changes, flash crowds and abuse. Recog... / to this is the development of intrusion detection tools such as Bro br and O. Niggemann Supporting intrusion detection by graph clustering and

A Software Fault Tree Approach to Requirements Analysis of an.. - Guy Helmer Johnny (2001)   (Correct)
The use of software fault trees for requirements identification and analysis in an Intrusion Detection System (IDS) is described. Intrusions are divided into seven stages, following Ruiu, and a fault ... / Requirements Analysis of an Intrusion Detection System Guy Helmer br and analysis in an Intrusion Detection System IDS is described.

Detecting Network Intrusions via a Statistical Analysis of Network.. - Bykova, Ostermann, Tjaden (2001)   (Correct)
With the growing threat of abuse of network resources, it becomes increasingly important to be able to detect malformed packets on a network and estimate the damage they can cause. Carefully construct... / data. Keywords-Intrusion Detection System suspicious br I. INTRODUCTION Intrusion detection takes a greater role in the

A Framework for Distributed Intrusion Detection using Interest Driven .. - Gopalakrishna, Spafford (2001)   (Correct)
Current distributed intrusion detection systems are not completely distributed with respect to data analysis because of the presence of centralized data analysis components. This deficiency has many u... /

Fault Tolerant Distributed Information Systems - Knight, Elder (2001)   (Correct)
Critical infrastructures provide services upon which society depends heavily; these applications are themselves dependent on distributed information systems for all aspects of their operation and so s... /

From Declarative Signatures to Misuse IDS - Jean-Philippe Pouzol And (2001)   (Correct)
In many existing misuse intrusion detection systems, intrusion signatures are very close to the detection algorithms. As a consequence, they contain too many cumbersome details. Recent work have pr... / In many existing misuse intrusion detection systems intrusion br to detect misuses. Among the intrusion detection systems IDS briefly

Indra: A Distributed Approach to Network Intrusion Detection and.. - Zhang, Janakiraman (2001)   (Correct)
While advances in computer and communications technology have made the network ubiquitous, they have also rendered networked systems vulnerable to malicious attacks orchestrated from a distance. The... / Approach to Network Intrusion Detection and Prevention Qi Zhang br or incidental damage. Intrusion detection involves identifying

An Expert System for Analyzing Firewall Rules - Eronen, Zitting (2001)   (Correct)
When deploying firewalls in an organization, it is essential to verify that the firewalls are configured properly. The problem of finding out what a given firewall configuration does occurs, for insta... / has been in the field of intrusion detection. Axelsson's survey br Stefan Axelsson. Intrusion detection systems A taxonomy and

Early Measurements of a Cluster-based Architecture for P2P Systems - Krishnamurthy, Wang, Xie (2001)   (Correct)
Peer-to-peer applications such as Napster, Freenet, and Gnutella, have gained much attention recently. These applications are mainly designed and used for largescale sharing of MP3 files. In such syst... / connections. When an intrusion detection system was triggered

Applying Mobile Agent Technology to Intrusion Detection - Krügel, Toth (2001)   (Correct)
The increasing number of network security related incidents makes it necessary for organizations to actively protect their sensitive data with the installation of intrusion detection systems (IDS). Au... / Mobile Agent Technology to Intrusion Detection Christopher Kr ugel br data with the installation of intrusion detection systems IDS Autonomous

Adele: An Attack Description Language For Knowledge-Based Intrusion.. - Michel, Mé (2001)   (Correct)
ADeLe is an attack description language designed to model a database of known attack scenarios. As the descriptions might contain executable attack code, it allows one to test the efficiency of given ... / Language For Knowledge-Based Intrusion Detection C Edric Michel br Keywords Intrusion detection attack description

"Why 6?" Defining the Operational Limits of stide, an Anomaly-Based.. - Tan, Maxion (2001)   (Correct)
The detection of masqueraders and novel attacks are two of the more difficult problems facing intrusion detection systems. While anomaly-based intrusion detection approaches appear to be among the mos... / difficult problems facing intrusion detection systems. While br systems. While anomaly-based intrusion detection approaches appear to be

SITAR: A Scalable Intrusion-Tolerant Architecture for Distributed.. - Feiyi Wang Fengmin (2001)   (Correct)
This paper presents a intrusion tolerant architecture for distributed services, especially COTS servers. It is motivated by two observations: First, no security precautions can guarantee that a system... / Intrusion tolerance intrusion detection and response distributed br Fengmin Gong is with Intrusion Detection Technology Division of

Application-Level Survivability: Resumable FTP - Grzywa, Yurcik, Brumbaugh (2001)   (Correct)
Internet attacks are moving up the protocol stack to the application layer, effectively blinding lower-layer security prevention and detection techniques. It has been estimated that 40% of unplanned s... / firewall and go undetected by intrusiondetection systems. In br allows creation of an active intrusion detection system that can be used to

Privacy Risks to Straddlers in Recommender Systems - Ramakrishnan, Keller, Mirza (2001)   (Correct)
We explore the conflict between personalization and privacy that arises from the existence of straddlers in a recommender system. A straddler is a person with eclectic tastes who rates products acros... / consultants for data mining intrusion detection for detecting suspicious

Defense-In-Depth Revisited: Qualitative Risk Analysis Methodology for .. - Silk (2001)   (Correct)
Defense-In-Depth [1] concepts for global information operations are physical boundary-centric. However, networkcentric operations are multidimensional, layered and often virtual. The interconnection o... / of logs audit trails intrusion detection systems etc. .

Argus - A distributed network-intrusion detection system - Singh, Kandula (2001)   (Correct)
Network-Intrusion Detection deals with identification and containment of network-based attacks. Such systems could be classified based on the medium they listen on (end-hosts or network segments), the... /

The Willow Survivability Architecture - Knight, Heimbigner, Wolf, Carzaniga, .. (2001)   (Correct)
this paper we summarize the Willow concepts and provide an overview of the Willow architecture. Finally we describe a demonstration application system that has been built on top of a prototype Willow ... /

An intelligent decision support system for intrusion detection and.. - Dasgupta, Gonzalez (2001)   (Correct)
The paper describes the design of a genetic classifier-based intrusion detection system, which can provide active detection and automated responses during intrusions. It is designed to be a sense and ... /

Translating Snort rules to STATL scenarios - Eckmann (2001)   (Correct)
that they include signatures for some collection of known attacks, and monitor an event stream looking for instances of any signature in their collection. There is an enormous duplication of effort w... /

Pattern Extraction for Time Series Classification - Geurts (2001)   (Correct)
In this paper, we propose some new tools to allow machine learning classifiers to cope with time series data. We first argue that many time-series classification problems can be solved by detecting an... / recognition of gestures intrusion detection.In spite of this it is

Analysis of a Statistics Counter Architecture - Devavrat Shah Sundar (2001)   (Correct)
Packet switches (e.g., IP routers, ATM switches and Ethernet switches) maintain statistics for a variety of reasons: performance monitoring, network management, security, network tracing, and traffic ... / stateful firewalling intrusion detection performance monitoring

Visual Traffic Monitoring and Evaluation - Erbacher (2001)   (Correct)
As computer networks and associated infrastructures become ever more important to the nation's commerce and communication, it is becoming exceedingly critical that these networks be managed effectivel... / is derived from our work on intrusion detection and our realization

Dealing with Denial-of-Service Attacks in Agent-enabled Active and.. - Karnouskos (2001)   (Correct)
Denial of Service (DoS) attacks is a well-known problem with victims even among prestigious commercial sites. Such attacks in traditional networking are difficult to recognize and to handle. An active... / be followed. Keywords Intrusion Detection Systems Distributed br and b to handle. Today's Intrusion Detection Systems IDS are static

An Achilles' Heel in Signature-Based IDS: Squealing False Positives.. - Patton, Yurcik, Doss (2001)   (Correct)
We report a vulnerability to network signature-based IDS which we have tested using Snort and we call "Squealing". This vulnerability has significant implications since it can easily be generalized ... /

Detecting Novel Attacks by Identifying Anomalous Network Packet.. - Mahoney, Chan (2001)   (Correct)
We describe a simple and efficient network intrusion detection algorithm that detects novel attacks by flagging anomalous field values in packet headers at the data link, network, and transport layers... / simple and efficient network intrusion detection algorithm that detects br In the DARPA off-line intrusion detection evaluation test set

Defense-In-Depth Revisited: Qualitative Risk Analysis Methodology For .. - Silk (2001)   (Correct)
Defense-In-Depth [1] concepts for global information operations are physical boundary-centric. However, network-centric operations are multidimensional, layered and often virtual. The interconnection ... / of logs audit trails intrusion detection systems etc. .

Visual Behavior Characterization For Intrusion Detection In Large.. - Erbacher (2001)   (Correct)
This work focuses on the visual representation of relations towards aiding the exploration and analysis of network intrusions. Fundamentally, the visual representations aid an analyst in comprehending... / Characterization For Intrusion Detection In Large Scale Systems br Information Visualization Intrusion Detection Computer Security .

Prediction-based Monitoring in Sensor Networks: Taking Lessons from.. - Goel (2001)   (Correct)
In this paper we discuss the problem of monitoring data sensed in large sensor networks. A sensor typically runs on a battery having a limited lifetime. In order to increase the lifetime of a sensor i... / example applications include intrusion detection gathering ground

Security Monitoring, Visualization, and System Survivability - Varner, Knight (2001)   (Correct)
Introduction A significant impediment to the development of large-scale survivable systems is the inability to accurately monitor these systems in real-time. Traditional methods of monitoring rely on... /

A New Intrusion Detection Method Based on Discriminant Analysis - Midori Asaka Regular (2001)   (Correct)
This paper explains our newmet6 d for tr separat48 intWE6::E and normal behavior by discriminant analysis, and describes tW classificatEP mets d by which t identen an unknown behavior unknown PAPER... /

Improved Class Probability Estimates from Decision Tree Models - Margineantu, Dietterich (2001)   (Correct)
Decision tree models typically give good classification decisions but poor probability estimates. In many applications, it is important to have good probability estimates as well. This paper introduce... / fraud detection or computer intrusion detection the cost of making a false

Intrusion Tolerance Approaches in ITUA - Cukier, Lyons, Pandey, Ramasamy.. (2001)   (Correct)
This paper presents an overview and the key aspects of the ITUA project. We will describe the kind of attacks we are considering, how unpredictability can be used for intrusion tolerance, the architec... /

High Resolution Traffic Measurement - Glenn Mansfield Sandeep (2001)   (Correct)
Measuring traffic at high resolution using standard mechanisms poses several problems. In this paper we discuss the problems and then describe the implementation of a system that measures network traf... / NIWH traffic pattern intrusion detection. I. INTRODUCTION br Network Intrusions In Intrusion Detection Systems Packet Contents Are

Randomly Roving Agents for Intrusion - Detection Ira Moskowitz (2001)   (Correct)
Agent based intrusion detection systems (IDS) have advantages such as scalability, reconfigurability, and survivability. In this paper, we introduce a mobile-agent based IDS, called ABIDE (Agent Bas... /

Computer Intrusion: Detecting Masquerades - Schonlau, DuMouchel, Ju, Karr.. (2001)   (Correct)
Masqueraders in computer intrusion detection are people who use somebody else's computer account. We investigate a number of statistical approaches for detecting masqueraders. To evaluate them, we col... / Masqueraders in computer intrusion detection are people who use somebody br Unix Introduction Intrusion detection in computer science is an

On-Line Intrusion Detection Using Sequences of System Calls - Snyder (2001)   (Correct)
viii 1. unknown SYSTEM CALLS Name: Damon Snyder Department: Department of Computer Science Major Professor: Robert van Engelen Major Professor: Kyle Gallivan Degree: Master of Science Term Degr... / On-Line Intrusion Detection Using Sequences Of System br techniques for on-line intrusion detection. A detailed analysis of

Secure Multi-Party Computation Problems and Their Applications: A.. - Du, Atallah (2001)   (Correct)
The growth of the Internet has triggered tremendous opportunities for cooperative computation, where people are jointly conducting computation tasks based on the private inputs they each supplies. The... /

Intrusion detection with unlabeled data using clustering - Portnoy (2001)   (Correct)
Intrusions pose a serious security threat in a network environment, and therefore need to be promptly detected and dealt with. New intrusion types, of which detection systems may not even be aware, ... /

An Experimental Study of Security Vulnerabilities Caused by Errors - Jun Xu Shuo (2001)   (Correct)
This paper presents an experimental study which shows that, for the Intel x86 architecture, single-bit control flow errors in the authentication sections of targeted applications can result in signifi... / encryption intrusion detection and anomaly detection br of environmental factors on intrusion detection systems Several

Use Of Passive Network Mapping To Enhance Signature Quality Of Misuse .. - Dayioglu, Ozgit (2001)   (Correct)
Misuse detection systems are known to be producing high rates of false positive alerts. High rates of false alerts adversely affect system usability and dynamic countermeasure generation. Network misu... / Quality Of Misuse Network Intrusion Detection Systems Burak br of self-learning for network intrusion detection systems. The collected

Windows Performance Monitoring and Data Reduction using - Knop (2001)   (Correct)
We describe and evaluate WatchTower, a system that simplifies the collection of Windows performance counter data for monitoring and usage profiling of Windows machines. WatchTower has overheads simila... / employee student output. Intrusion detection Unusual behavior could be br And So- Mayaji A. Intrusion Detection Using Sequences Of System

The Artificial Immune System for Network Intrusion Detection: - An Investigation Of (2001)   (Correct)
This paper explores the use of an artificial immune system (AIS) for network intrusion detection. As one significant component for a complete AIS, static clonal selection with a negative selection ope... /

The Glasshouse - A Reflective Container for Mobile Code - Welch (2001)   (Correct)
this paper have drawn upon discussions with him unknown The Glasshouse - A Reflective Container for Mobile Code Ian S. Welch Department of Computing University of Newcastle upon Tyne Email: i.s.we... /

Distributed Network Defense - Frincke, Wilhite (2001)   (Correct)
We propose a new paradigm for network defense: a hierarchical network of lightweight, mobile and adaptive tools combined with a distributed, collaborative intrusion detection environment. Agents are i... /

Evolution in Distributed Heterogeneous Systems - Devanbu, Wohlstadter (2001)   (Correct)
Distributed, heterogeneous systems are becoming very common, as globalized organizations integrate applications running on di#erent platforms, possibly written in di#erent languages. Component-interop... / -service monitoring for intrusion detection and administrative

A Study Of Several Specific Secure Two-Party Computation Problems - Du (2001)   (Correct)
Alice has a private input $x$ (of any data type, such as a number, a matrix or a data set). Bob has another private input $y$. Alice and Bob want to cooperatively conduct a specific computation on $x$... /

Meta-Learning in Distributed Data Mining Systems: Issues and.. - Prodromidis, Chan, al. (2000)   (Correct)
Data mining systems aim to discover patterns and extract useful information from facts recorded in databases. A widely adopted approach to this objective is to apply various machine learning algorithm... / been successfully applied to intrusion detection in network-based systems br Chan. Agentbased fraud and intrusion detection in financial information

MAFTIA - reference Model and Use Cases - Cachin, Camenisch, Dacier, Deswarte, .. (2000)   (Correct)
This document constitutes the first deliverable of MAFTIA work package 1. The objective of this work package is to define a consistent framework for ensuring the dependability of distributed appl... / . Multinational Intrusion Detection Systems br Figure -Intrusion-detection and Tolerance Framework

String Pattern Matching For A Deluge Survival Kit - Apostolico, Crochemore (2000)   (Correct)
String Pattern Matching concerns itself with algorithmic and combinatorial issues related to matching and searching on linearly arranged sequences of symbols, arguably the simplest possible discrete s... / dynamics genome studies intrusion detection and countless other br Prediction to Data Mining Intrusion Detection and Security Protein and

Intrusion Detection Systems: A Survey and Taxonomy - Axelsson (2000)   (Correct)
This paper presents a taxonomy of intrusion detection systems that is then used to survey and classify a number of research prototypes. The taxonomy consists of a classification first of the detection... / Intrusion Detection Systems A Survey and br paper presents a taxonomy of intrusion detection systems that is then used

Selecting Examples for Partial Memory Learning - Maloof, Michalski (2000)   (Correct)
This paper describes a method for selecting training examples for a partial memory learning system. The method selects extreme examples that lie at the boundaries of concept descriptions and uses th... / problem and a computer intrusion detection problem. Experimental br and computer intrusion detection Maloof Michalski

Architecture for an Artificial Immune System - Hofmeyr, Forrest (2000)   (Correct)
An artificial immune system (ARTIS) is described which incorporates many properties of natural immune systems, including diversity, distributed computation, error tolerance, dynamic learning and ada... / in the form of a network intrusion detection system called LISYS. LISYS br and implemented LISYS an intrusion detection system that monitors

Artificial Immune Systems: Part II - A Survey Of Applications - de Castro, Von Zuben (2000)   (Correct)
this report (De Castro & Von Zuben, 1999) is intended to present the basic theory and concepts necessary for the development of immune-based systems. It brings an instructive introduction to the mamma... / immune system for network intrusion detection. br of the proposed multi-agent intrusion detection system.

Practical Network Security: Experiences with ntop - Deri, Suin (2000)   (Correct)
This paper shows how ntop can also be unknown Practical Network Security: Experiences with ntop Luca Deri and Stefano Suin 2 1 Finsiel S.p.A., Via Matteucci 34/b, 56124 Pisa. Email l.deri@finsi... / monitoring network security intrusion detection TCP IP. . Introduction br it into a sophisticated intrusion detection system The goal of

Detecting Intrusions in Security Protocols - Yasinsac (2000)   (Correct)
Secure electronic communication relies on the application of cryptography. However, even with perfect encryption, communication may be compromised without effective security protocols for key exchange... / method is based on classic intrusion detection techniques of br protocol verification and intrusion detection. The following sections

PNrule: A New Framework for Learning Classifier Models in Data Mining .. - Agarwal, Joshi (2000)   (Correct)
We have developed a new solution framework for the multi-class classification problem in data mining. The method is especially applicable in situations where different classes have widely different d... / A Case-Study in Network Intrusion Detection Ramesh Agarwal br the technique to the Network Intrusion Detection Problem KDD-CUP' Our

Towards Higher Disk Head Utilization: Extracting Free Bandwidth From.. - Lumb, Schindler, Ganger, Nagle (2000)   (Correct)
Freeblock scheduling is a new approach to utilizing more of a disk's potential media bandwidth. By filling rotational latency periods with useful media transfers, 20-50% of a never-idle disk's bandwid... /

Mobile Agents In Intrusion Detection And Response - Jansen, Mell, Karygiannis, Marks (2000)   (Correct)
Effective intrusion detection capability is an elusive goal, not solved easily or with a single mechanism. However, mobile software agents go a long way toward realizing the ideal behavior desired in ... / Mobile Agents In Intrusion Detection And Response W. br Abstract Effective intrusion detection capability is an elusive

A Framework for Constructing Features and Models for Intrusion.. - Lee, Stolfo (2000)   (Correct)
This paper describes a novel framework, MADAM ID, for Mining Audit Data for Automated Models for Intrusion Detection. This framework uses data mining algorithms to compute activity patterns from syste... / Features and Models for Intrusion Detection Systems Wenke Lee North br Stolfo Columbia University Intrusion detection ID is an important

Mining Frequent Itemsets Using Support Constraints - Wang, He, Han (2000)   (Correct)
Interesting patterns often occur at varied levels of support. The classic association mining based on a uniform minimum support, such as Apriori, either misses interesting patterns of low support ... / frequent itemsets to build intrusion detection models LSM to con- br Mining audit data to build intrusion detection models. KDD -

Model-Based Analysis of Configuration Vulnerabilities - Ramakrishnan, Sekar (2000)   (Correct)
Vulnerability analysis is concerned with the problem of identifying weaknesses in computer systems that can be exploited to compromise their security. In this paper we describe a new approach to vuln... / patterns for misuse intrusion detection. When vulnerabilities are br vulnerable systems is misuse intrusion detection where system use is

Machine Learning Techniques For The Computer Security Domain Of.. - Lane (2000)   (Correct)
xv 1 unknown MACHINE LEARNING TECHNIQUES FOR THE COMPUTER SECURITY DOMAIN OF ANOMALY DETECTION of Purdue University by T... / in the design of distributed intrusion detection systems br in the AAFID hierarchical intrusion detection system The target

STATL: An Attack Language for State-based Intrusion Detection - Eckmann, Vigna, Kemmerer (2000)   (Correct)
STATL is an extensible state/transition-based attack description language designed to support intrusion detection. The language allows one to describe computer penetrations as sequences of actions th... / Language for State-based Intrusion Detection Steven T. Eckmann br language designed to support intrusion detection. The language allows one

Doing intrusion detection using embedded sensors - Zamboni (2000)   (Correct)
Intrusion detection systems have usually been developed using large host-based components. These components impose an extra load on the system where they run (sometimes even requiring a dedicated syst... / Doing intrusion detection using embedded sensors br Abstract Intrusion detection systems have usually been

Transport and Application Protocol Scrubbing - Robert Malan David (2000)   (Correct)
This paper describes the design and implementation of a protocol scrubber, a transparent interposition mechanism for explicitly removing network attacks at both the transport and application protocol ... / passive network-based intrusion detection systems whereas the br active network-based intrusion detection systems. The transport

Intrusion Detection in Wireless Ad-Hoc Networks - Zhang, Lee (2000)   (Correct)
As the recent denial-of-service attacks on several major Internet sites have shown us, no open computer network is immune from intrusions. The wireless ad-hoc network is particularly vulnerable due to... / Intrusion Detection in Wireless Ad-Hoc Networks br line of defense. Many of the intrusion detection techniques developed on a

Benchmarking Anomaly-Based Detection Systems - Roy Maxion Kymie (2000)   (Correct)
Anomaly detection is a key element of intrusiondetection and other detection systems in which perturbations of normal behavior suggest the presence of intentionally or unintentionally induced attacks,... / detection is a key element of intrusiondetection and other detection systems br characteristics. In intrusion-detection settings however this is

Detecting Backdoors - Zhang, Paxson (2000)   (Correct)
Backdoors are often installed by attackers who have compromised a system to ease their subsequent return to the system. We consider the problem of identifying a large class of backdoors, namely those ... / network traffic using an intrusion detection system IDS where we br In general network intrusion detection becomes much more

A Data Mining and CIDF Based Approach for Detecting Novel and.. - Lee, Nimbalkar, Yee, Patil, Desai.. (2000)   (Correct)
As the recent distributed Denial-of-Service (DDOS) attacks on several major Internet sites have shown us, no open computer network is immune from intrusions. Furthermore, intrusion detection syste... / from intrusions. Furthermore intrusion detection systems IDSs need to be br system based on the Common Intrusion Detection Framework CIDF where

The STAT Tool Suite - Vigna, Eckmann, Kemmerer (2000)   (Correct)
This paper describes a suite of intrusion detection tools developed by the Reliable Software Group at UCSB. The tool suite is based on the State Transition Analysis Technique (STAT), in which compute... / paper describes a suite of intrusion detection tools developed by the br and tailored to perform intrusion detection in different domains and

Software Tamper Resistance: Obstructing Static Analysis of Programs - Wang, Hill, Knight, Davidson (2000)   (Correct)
In this paper we address the problem of protecting trusted software on untrusted hosts by code obfuscation. We address one aspect of the problem, namely obstructing static analysis of programs. The p... / it arises for example in intrusiondetection systems. The parts of the br systems. The parts of the intrusion-detection system that record events

Intrusion Detection Systems & Multisensor Data Fusion: Creating.. - Bass (2000)   (Correct)
Next generation cyberspace intrusion detection (ID) systems will require the fusion of data from myriad heterogeneous distributed network sensors to effectively create cyberspace situational awareness... / For Publication draft Intrusion Detection Systems Multisensor Data br Next generation cyberspace intrusion detection ID systems will require

A Preliminary Attempt to Apply Detection and Estimation Theory to.. - Department (2000)   (Correct)
Research into the automated detection of computer security violations is hardly in its infancy, yet little comparison has been made with the established field of detection and estimation theory, the r... / and Estimation Theory to Intrusion Detection Stefan Axelsson br studying the problem of intrusion detection by the use of the

Active Trust Management for Autonomous Adaptive Survivable Systems - Shrobe, Doyle, Szolovits (2000)   (Correct)
Contents 1 Innovative Claims 1 2 Technical Rationale 2 2.1 A Scenario . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 2.2 Trust in Survivable Systems: An Overview . . . . ... / the application itself and intrusion detection systems. . The br traffic from outside the lab. Intrusion Detection systems report that

Framework of Multi-agents Internet Security System - Ayesh, Bechkoum (2000)   (Correct)
Software agents are playing an increasing variety of roles in helping with automating Internet related tasks such as searching and electronic commerce [1]. Such agents are being used, or investigated,... / we discuss the issue of intrusion detection which is the result

Supporting Intrusion Detection by Graph Clustering and Graph Drawing - Tolle, Niggemann (2000)   (Correct)
This paper presents a description of a system supporting the detection of intrusions and network anomalies by analyzing and visualising traffic flows in computer networks. The system supervises the ty... / Supporting Intrusion Detection by Graph Clustering and br detection component of an Intrusion Detection System. Events are

User-Level Infrastructure for System Call Interposition: A Platform.. - Jain, Sekar (2000)   (Correct)
Several new approaches for detecting malicious attacks on computer systems and/or confining untrusted or malicious applications have emerged over the past several years. These techniques often rely on... / A Platform for Intrusion Detection and Confinement K. Jain br mechanisms as well as the intrusion detection confinement systems are

Evaluating Intrusion Detection Systems: The 1998 DARPA Off-line.. - Lippmann, Fried, Graf, Haines.. (2000)   (Correct)
A intrusion detection evaluation test bed was developed which generated normal traffic similar to that on a government site containing 100's of users on 1000's of hosts. More than 300 instances of 38 ... / Evaluating Intrusion Detection Systems The DARPA br The DARPA Off-line Intrusion Detection Evaluation Richard P.

Detecting Stepping Stones - Zhang, Paxson (2000)   (Correct)
One widely-used technique by which network attackers attain anonymity and complicate their apprehension is by employing stepping stones: they launch attacks not from their own computer but from inter... / While as with most forms of intrusion detection with enough diligence br . Accuracy As with intrusion detection in general we face the

A Formal Methods Case Study: Using "light-weight" VDM for the.. - Droschl, Kuhn, Sonneck, Thuswald (2000)   (Correct)
This paper describes a formal methods case study in which one module of an existing security system was re-developed using the "light-weight" Vienna Development Method supported by the IFAD Toolb... / automatic door control intrusion detection night-guard supervision

Toward Cost-Sensitive Modeling for Intrusion Detection - Lee (2000)   (Correct)
Intrusion detection systems need to maximize security while minimizing costs. In this paper, we study the problem of building cost-sensitive intrusion detection models. We examine the major cost fac... / Cost-Sensitive Modeling for Intrusion Detection Wenke Lee Computer br Abstract Intrusion detection systems need to maximize

Self-Securing Storage: Protecting Data in Compromised Systems - Strunk, Goodson, Scheinholtz.. (2000)   (Correct)
Self-securing storage prevents intruders from undetectably tampering with or permanently deleting stored data. To accomplish this, self-securing storage devices internally audit all requests and keep ... / techniques can extend the intrusion detection window oered by br discovered by an automated intrusion detection system IDS or by a

Building Adaptive and Agile Applications Using Intrusion Detection.. - Loyall, Pal, Schantz, Webber (2000)   (Correct)
Traditional Intrusion Detection Systems (IDSs) mostly work off-line, without any direct runtime interaction or coordination with the applications (and with other IDSs) that they aim to protect. Includ... / and Agile Applications Using Intrusion Detection and Response Joseph P. br Abstract Traditional Intrusion Detection Systems IDSs mostly work

Toward Cost-Sensitive Modeling for Intrusion Detection and Response - Lee, Fan, Miller, Stolfo, Zadok (2000)   (Correct)
Intrusion detection systems (IDSs) must maximize the realization of security goals while minimizing costs. In this paper, we study the problem of building cost-sensitive intrusion detection models. W... / Cost-Sensitive Modeling for Intrusion Detection and Response Wenke Lee br Abstract Intrusion detection systems IDSs must

Ubiquitous and Robust Authentication Services for Ad Hoc Wireless.. - Luo, Lu (2000)   (Correct)
Providing security support for large ad hoc wireless networks is challenging due to their unique characteristics, such as mobility, channel errors, dynamic node joins and leaves, and occasional node b... / our design works with any intrusion detection algorithms and mechanisms br studies the problem of intrusion detection in ad hoc networks. While

The Middleware Architecture of MAFTIA: A Blueprint - Verssimo, Neves, Correia (2000)   (Correct)
In this paper, we present the middleware architecture of MAFTIA, an ESPRIT project aiming at developing an open architecture for transactional operations on the Internet. The former is a modular and... / states can be unveiled by intrusion detection as we will see ahead but br systems generically known as Intrusion Detection Systems IDS Although an

Detecting and Displaying Novel Computer Attacks with Macroscope - Cunningham, al. (2000)   (Correct)
Macroscope is a network-based intrusion detection system that uses Bottleneck Verification to detect user-to-superuser attacks. Bottleneck Verification (BV) detects novel computer attacks by looking f... / is a network-based intrusion detection system that uses Bottleneck br attacks. Index terms-intrusion detection security bottleneck

An Architecture For Protection Of Network Hosts From Denial Of.. - Balasubramanian (2000)   (Correct)
As we prepare ourselves to take a joyride in the ubiquitous computing world of the 21st century, we must also be prepared to face the challenges from the netherworld of hackers, who now have avenues t... / . Need for a Generic Intrusion Detection br . Intrusion Detection Systems

Intrusion Detection in Real-time Database Systems Via Time Signatures - Lee, Stankovic, Son (2000)   (Correct)
In this paper, we describe a method for intrusion detection applied to real-time database systems. The novel idea pursued in this study is to exploit the real-time properties of data in intrusion dete... / Intrusion Detection in Real-time Database br we describe a method for intrusion detection applied to real-time

Managing Distributed Systems with Smart Subscriptions - Filman, Lee (2000)   (Correct)
We describe an event-based, publish and subscribe system based on using "smart subscriptions" to recognize weakly structured events. We present a hierarchy of subscription languages (propositional, pr... / -fault diagnosis intrusion detection performance analysis and br such as fault diagnosis intrusion detection performance analysis and

Detecting Network Intrusion Using a Markov Modulated Nonhomogeneous.. - Scott (2000)   (Correct)
Network intrusion occurs when a criminal gains access to a customer's telephone, computer, bank, or other type of account. Detecting network intrusion is an important problem that has received little ... / unauthorized traffic. Network intrusion detection is of great interest to br the World Wide Web. Network intrusion detection involves monitoring the

Lightweight Agents For Intrusion Detection - Helmer, Wong, Honavar, Miller (2000)   (Correct)
We have designed and implemented an intrusion detection system prototype based on mobile agents. Our agents travel between monitored systems in a network of distributed systems, obtain information f... / Lightweight Agents For Intrusion Detection Guy Helmer Johnny br designed and implemented an intrusion detection system prototype based on

Adaptive Model Generation for Intrusion Detection Systems - Eskin, Miller, Zhong, Yi, Lee, Stolfo (2000)   (Correct)
In this paper, we present adaptive model generation, a method for automatically building detection models for data-mining based intrusion detection systems. Using the same data collected by intrusion ... / Model Generation for Intrusion Detection Systems Eleazar Eskin br models for data-mining based intrusion detection systems. Using the same

Adaptive Intrusion Detection: a Data Mining Approach - Lee, Stolfo, Mok (2000)   (Correct)
In this paper we describe a data mining framework for constructing intrusion detection models. The first key idea is to mine system audit data for consistent and useful patterns of program and user ... / Adaptive Intrusion Detection a Data Mining Approach br framework for constructing intrusion detection models. The first key idea

Adaptation Techniques for Intrusion Detection and Intrusion Response.. - Ragsdale, Carver, Humphries, Pooch (2000)   (Correct)
This paper examines techniques for providing adaptation in intrusion detection and intrusion response systems. As attacks on computer systems are becoming increasingly numerous and sophisticated, ther... / Adaptation Techniques for Intrusion Detection and Intrusion Response br for providing adaptation in intrusion detection and intrusion response

A Multiple Model Cost-Sensitive Approach for Intrusion Detection - Fan, Lee, Stolfo, Miller (2000)   (Correct)
Intrusion detection systems (IDSs) need to maximize security while minimizing costs. In this paper, we study the problem of building cost-sensitive intrusion detection models to be used for realti... / Cost-Sensitive Approach for Intrusion Detection Wei Fan Wenke br Abstract. Intrusion detection systems IDSs need to

Collaboration Requirements: A Point of Failure in Protecting.. - Wiederhold (2000)   (Correct)
There are settings where we have to collaborate with individuals and organizations who, while not being enemies, should not be fully trusted. Collaborators must be authorized to access information sys... / be used to implement pure intrusion detection since it can be br efforts rapidly. B. Intrusion Detection Result checking can

Building Survivable Systems: An Integrated Approach based on.. - Bowen, Chee, Segal, Sekar, Shanbhag, .. (2000)   (Correct)
Reliance on networked information systems to support critical infrastructures prompts interest in making network information systems survivable, so that they continue functioning even when under attac... / Integrated Approach based on Intrusion Detection and Damage Containment br of the art in event based intrusion detection by developing a

Anomaly Detection over Noisy Data using Learned Probability.. - Eskin (2000)   (Correct)
Traditional anomaly detection techniques focus on detecting anomalies in new data after training on normal (or clean) data. In this paper we present a technique for detecting anomalies without trainin... / technique is applied to intrusion detection by examining intrusions br is an important problem in intrusion detection Denning Intrusion

Formal Specification of a Security System Module in VDM-SL - Droschl (2000)   (Correct)
Essentially, the Compileable Security System (CSS) provides access control at sites like banks. The objective of the subsystem driver 0E (SSD-0E) is to support night guards on their way through pre-de... / automatic door control intrusion detection and fire alarms. CSS br on duty obstacles like intrusion detection-circuits and a human

On Achieving Fast Damage Appraisal in case of Cyber Attacks - Session Ta Chandana (2000)   (Correct)
After the detection of a cyber attack, damage in an affected database system needs to be appraised immediately. For damage assessment, traditional recovery methods require the log of the affected data... / There are numerous intrusion detection techniques available today br T. F. Lunt A Survey of Intrusion Detection Techniques Computers

Towards an Active IP Accounting Infrastructure - Franco Travostino Nortel (2000)   (Correct)
Traditional IP accounting infrastructures cannot withstand the shock waves produced by voice over IP integration, increasingly large accounting data volumes, adaptive pricing schema that reflect resou... / sampled-e.g.for billing intrusion detection or traffic monitoring

IDS/A: An Interface between Intrusion Detection System and Application - Hutchison, Welz (2000)   (Correct)
We describe a number of problems which may reduce the effectiveness of a conventional network intrusion detection system. These problems are the result of the IDS having to second-guess the components... / IDS A An Interface between Intrusion Detection System and Application br of a conventional network intrusion detection system. These problems are

Intrusion Detection Systems and Multisensor Data Fusion - Bass (2000)   (Correct)
This article provides a brief review of ID concepts and terms, an overview of the art and science of multisensor data-fusion technology, and introduces the ID systems data-mining environment as a comp... / v No. Intrusion Detection Systems And br Next-generation cyberspace intrusion detection ID systems will require

Probabilistic Networks with Undirected Links for Anomaly Detection - Mingming (2000)   (Correct)
In this paper we present our experience in applying Bayesian probabilistic networks to intrusion detection through anomaly detection. A Bayesian network (BN) is a graphical model that can encode prior... / probabilistic networks to intrusion detection through anomaly detection. br promising performance in intrusion detection. Keywords Bayesian

'Snortnet' - A Distributed Intrusion Detection System - Fyodor (2000)   (Correct)
Contents 1 Introduction 2 1.1 Intrusion Detection System Technology . . . . . . . . . . . . . 2 1.2 Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 2 IDS nowadays 6 2.1 Intrusio... / 'snortnet' A Distributed Intrusion Detection System Yarochkin Fyodor br Introduction . Intrusion Detection System Technology .

Data collection mechanisms for intrusion detection systems - Spafford, Zamboni (2000)   (Correct)
Drawing from the experience obtained during the development and testing of a distributed intrusion detection system, we reflect on the data collection needs of intrusion detection systems, and on the ... / collection mechanisms for intrusion detection systems Eugene br and testing of a distributed intrusion detection system we re ect on the

CiteSeer - citeseer.org - Terms of Service - Privacy Policy - Copyright © 1997-2002 NEC Research Institute