| J. Doyle, I. Kohane, W. Long, H. Shrobe, P. Szolovits, Event recognition beyond signature and anomaly, In Proceedings of the Second IEEE SMC Information Assurance Workshop. IEEE, IEEE Computer Society, June 2001 |
....and provide the appropriately processed inputs for making monitoring decisions. We believe that trend templates and associated matching mechanisms provide an approach to event recognition that goes beyond the capabilities standard signature and anomaly methods and their direct combinations. See [5] for an extended discussion. 8.2. Alerting models The library of alerting models incorporates both extant procedures for making alerting decisions and methods for convenient specification of utility information. The medical informatics literature contains an unsystematic variety of alerting ....
....intrusions, and anomaly based detection methods serve to identify temporal intervals in which things differ from expectations. The events one can characterize using trend templates appear to go beyond the capabilities of standard signature and anomaly methods and their simple combinations [5]. 10. Related work The MAITA architecture has significant similarities to the architecture used in the EMERALD intrusion detection system [21, 27] The basic EMERALD system provides a distributed set of monitoring processes or capabilities, organized hierarchically in a way that scales with the ....
J. Doyle, I. Kohane, W. Long, H. Shrobe, and P. Szolovits. Event recognition beyond signature and anomaly. In Proceedings of the Second IEEE SMC Information Assurance Workshop. IEEE, IEEE Computer Society, June 2001.
No context found.
J. Doyle, I. Kohane, W. Long, H. Shrobe, P. Szolovits, Event recognition beyond signature and anomaly, In Proceedings of the Second IEEE SMC Information Assurance Workshop. IEEE, IEEE Computer Society, June 2001
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC