| S. Staniford, S. Cheung, R. Crawford, M. Dilger, J.Frank, J. Hoagland, K. Levitt, C. Wee, R. Yip, D. Zerkle, GrIDS. A graph-based intrusion detection system for large networks, National Information Systems Security Conference, Baltimore, MD, October 1996 |
....calls a program makes, and the intrusion detector tries to decide whether a given execution trace re ects normal behavior for that program. The idea of looking for features that identify malicious execution traces brings to mind the idea of signature detection. Many signature detection systems [5, 7] do exactly that: look for features that might be used to identify malicious programs. Unfortunately, the signatures in question are usually created by hand, and this is time consuming. It is also hard to determine how well a signaturebased system generalizes. Finally, existing signature detection ....
S. Staniford-Chen, S. Cheung, R. Crawford, M. Dilger, J. Frank, J. Hoagland, K. Levitt, C. Wee, R. Yip, and D. Zerkle. GrIDS { A Graph Based Intrusion Detection System for Large Networks. In Proceedings of the 19th National Information Systems Security Conference, 1996.
....is the main vulnerability of all current IDSs. The approach depicted in [14] presents a distributed information gathering step, but the drawbacks are the same: the centralized analyzing process is hazardous and recon gurability and scalability are limited. Subsequent works like [24] [22] or [3] present a fully distributed architecture: data collection and information analysis are performed without central authority. The authors hence answer to the scalability problem. Despite that, the 1 Internal or external to the overseen network. IDS itself, being static, still endures the ....
S. Staniford-Chen, S. Cheung, R. Crawford, M. Dilger, J. Frank, J. Hoagland, K. Levitt, C. Wee, R. Yip, and D. Zerkle. GrIDS{A graph based intrusion detection system for large networks. In Proc. 19th NIST-NCSC National Information Systems Security Conference, pages 361-370, 1996.
.... policy o real batch host passive distributed distributed low low IDIOT [34] 1994 policy real p continuous host passive centralised centralised low higher NIDES [1] 1995 hybrid real q continuous host r passive centralised distributed low s higher t GrIDS [53] 1996 hybrid u non real batch both v passive distributed distributed low low CSM [58] 1996 policy real continuous host active w distributed distributed low low Janus [17] 1996 policy real continous host active x centralised centralised low low JiNao [15] ....
....put together. 16 This of course, of great value to the research community. 2.15 GrIDS A graph based intrusion detection system for large networks 2. 15.1 Introduction The authors suggest a method for constructing graphs of the network activity in large networks, to aid in intrusion detection [53]. The graphs typically codify hosts on the networks as nodes, and connections between hosts as edges between these nodes. Which trac is chosen to represent activity in the form of edges is decided on the basis of user supplied rule sets. The graph globally, and the edges locally, have attributes, ....
S. Staniford Chen, S. Cheung, R. Crawford, M. Dilger, J. Frank, J. Hoagland, K Levitt, C. Wee, R. Yip, and D. Zerkle. GrIDS|A graph based intrusion detection system for large networks. In Proceedings of the 19th National Information Systems Security Conference, 1996.
No context found.
S. Staniford, S. Cheung, R. Crawford, M. Dilger, J.Frank, J. Hoagland, K. Levitt, C. Wee, R. Yip, D. Zerkle, GrIDS. A graph-based intrusion detection system for large networks, National Information Systems Security Conference, Baltimore, MD, October 1996
No context found.
S. Staniford, S. Cheung, R. Crawford, M. Dilger, J.Frank, J. Hoagland, K. Levitt, C. Wee, R. Yip, D. Zerkle, GrIDS. A graph-based intrusion detection system for large networks, National Information Systems Security Conference, Baltimore, MD, October 1996
No context found.
Staniford-Chen, S., Cheung, S., Crawford, R., Dilger, M., Frank, J., Hoagland, J., Levitt, K., Wee, C., Yip, R., and Zerkle, D. (1996). GrIDS A Graph-Based Intrusion Detection System for Large Networks. In Proc. of the 19th National Information Systems Security Conference.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC