(Enter summary)
Abstract: This paper presents a hierarchical model
to support attack specification and event abstraction in distributed intrusion detection. The model involves three
concepts: system view, signature, and view definition. A system view provides an abstract interface of a particular
type of information; defined on the instances of system views, a signature specifies certain distributed attacks or
events to be monitored; a view definition is then used to derive information from the matches of a signature... (Update)
Cited by: More
Techniques and Tools for Analyzing Intrusion Alerts - Ning, Cui, Reeves, Xu (2004)
(Correct)
Analyzing Intensive Intrusion Alerts Via Correlation - Peng Ning Yun (2002)
(Correct)
Scoping Security Issues for Interactive Grids - Dwoskin, Basu, Talwar, Kumar, .. (2003)
(Correct)
Similar documents (at the sentence level):
55.4%: Abstraction-Based Intrusion Detection In - Distributed Environments Peng
(Correct)
Active bibliography (related documents): More All
6.9: Abstraction-based Intrusion Detection in Distributed.. - Ning, Jajodia, Wang (2001)
(Correct)
1.3: Intrusion Detection: A Bibliography - Mé, Michel (2001)
(Correct)
1.0: Modeling Requests among Cooperating Intrusion Detection Systems - Ning, Wang, Jajodia (2000)
(Correct)
Similar documents based on text: More All
0.6: Correlating Alerts Using Prerequisites of Intrusions - Ning, Reeves, Cui (2001)
(Correct)
0.6: Cards: A Distributed System For Detecting Coordinated Attacks - Yang, Ning, Wang, Jajodia (2000)
(Correct)
0.4: Generating Market Basket Data with Temporal Information - Li, Ning, Wang, Jajodia
(Correct)
Related documents from co-citation: More All
6: LAMBDA: A Language to Model a Database for Detection of Attacks (context) - Cuppens, Ortalo
6: requireprovide model computer attack
- Templeton, requires et al. - 2000
5: Abstraction-based misuse detection: High-level specications and adaptable strate..
- Lin, Wang et al. - 1998
BibTeX entry: (Update)
P. Ning, S. Jajodia, and X. S. Wang. Abstraction-based intrusion detection in distributed environments. Information and System Security, 4(4):407--452, 2001. http://citeseer.ist.psu.edu/ning01abstractionbased.html More
@article{ ning01abstractionbased,
author = "Peng Ning and Sushil Jajodia and Xiaoyang Sean Wang",
title = "Abstraction-based intrusion detection in distributed environments",
journal = "Information and System Security",
volume = "4",
number = "4",
pages = "407-452",
year = "2001",
url = "citeseer.ist.psu.edu/ning01abstractionbased.html" }
Citations (may not include all citations):
1044
Maintaining knowledge about temporal intervals (context) - Allen - 1983
162
Implementation techniques for main memory database systems (context) - DeWitt, Katz et al. - 1984
132
EMERALD: Event monitoring enabling response to anomalous liv..
- Porras, Neumann - 1997
121
Network intrusion detection (context) - Mukherjee, Heberlein et al. - 1994
105
State transition analysis: A rule-based intrusion detection ..
- Ilgun, Kemmerer et al. - 1995
99
Temporal reasoning based on semi-intervals
- Freksa - 1992
79
Computer security threat monitoring and surveillance (context) - Anderson - 1980
78
Analysis of a denial of service attack on TCP
- Schuba, Krsul et al.
70
A data mining framework for building intrusion detection mod..
- Lee, Stolfo et al.
62
The NIDES statistical component: Description and justificati.. (context) - Javits, Valdes - 1993
59
USTAT: A real-time intrusion detection system for UNIX
- Ilgun - 1993
58
A pattern matching model for misuse intrusion detection
- Kumar, Spafford - 1994
50
NetSTAT: A network-based intrusion detection system
- Vigna, Kemmerer - 1999
48
Classification and Detection of Computer Intrusions
- Kumar - 1995
43
NADIR: An automated system for detecting network intrusion a.. (context) - Hochberg, Jackson et al. - 1993
42
A First Course in Database Systems (context) - Ullman, Widom - 1997
39
Detecting computer and network misuse through the production..
- Lindqvist, Porras
38
Cooperating security managers: A peer-based intrusion detect.. (context) - White, Fisch et al. - 1996
38
Haystack: An intrusion detection system (context) - Smaha - 1988
35
A database of computer attacks for the evaluation of intrusi..
- Kendall - 1999
34
NetSTAT: A network-based intrusion detection approach
- Vigna, Kermmerer - 1998
22
Abstraction-based misuse detection: High-level specification..
- Lin, Wang et al. - 1998
22
Abstraction-Based Misuse Detection: High-level Specification..
- Lin - 1998
22
Intrusion detection using autonomous agents (context) - Spafford, Zamboni - 2000
21
distributed intrusion detection system) - motivation (context) - Snapp, Brentano et al. - 1991
21
The blocks extensible exchange protocol core (context) - Rose - 2001
20
Languages and Tools for Rule-Based Distributed Intrusion Det.. (context) - Mounji - 1997
18
Intrusion detection message exchange format data model and e.. (context) - Curry, Debar - 2001
17
Design and implementation of a scalable intrusion detection ..
- Jou, Gong et al. - 2000
16
Network Intrusion Detection: An Analyst's Handbook (context) - Northcutt - 1999
15
A common intrusion detection framework (context) - Kahn, Porras et al. - 1998
14
NSTAT: A model-based real-time network intrusion detection s..
- Kemmerer - 1997
12
Security and privacy for partial order time
- Tygar - 1994
11
Deciduous: Decentralized source identification for network-b.. (context) - Chang, Narayan et al. - 1999
10
A framework for cooperative intrusion detection
- Frincke, Tobin et al. - 1998
9
A data mining and CIDF based approach for detecting novel an..
- Lee, Nimbalkar et al. - 2000
9
JiNao: Design and implementation of a scalable intrusion det..
- Wu, Chang et al.
9
Macmillan Technology Publishing (context) - Bace - 2000
8
Holding intruders accountable on the internet
- Staniford-Chen, Heberlein
8
Detecting novel network intrusion using bayes estimators (context) - Barbara, Wu et al. - 2001
7
A common intrusion specification language (context) - Feiertag, Kahn et al. - 2000
7
CARDS: A distributed system for detecting coordinated attack..
- Yang, Ning et al. - 2000
7
The common intrusion detection framework architecture (context) - Porras, Schnackenberg et al. - 1998
7
GrIDS - a graph based intrusion detection system for large n..
- Staniford-Chen, Cheung et al. - 1996
7
Intrusion detection inter-component adaptive negotiation
- Feiertag, Rho et al. - 2000
7
A security analysis of the NTP protocol version (context) - Bishop - 1990
6
Internetwork security monitor: An intrusion-detection system.. (context) - Heberlein, Mukherjee et al. - 1992
6
Using embedded sensors for detecting network attacks
- Kerschbaum, Spafford et al. - 2000
5
Communication in the common intrusion detection framework (context) - Kahn, Bolinger et al. - 1998
5
and intrusion detection (context) - Ho, Frincke et al. - 1998
4
Modeling requests among cooperating intrusion detection syst..
- Ning, Wang et al. - 2000
3
Architecture for real-time data management: Timesten's core .. (context) - Software - 2001
3
A query facility for common intrusion detection framework
- Ning, Wang et al. - 2000
2
Internet Draft draft-ietf-idwg-beep-tunnel (context) - New, profile - 2001
2
Towards tracing hidden attackers on untrusted IP networks (context) - Chang, Wu et al. - 2000
2
Internet Draft draft-ietf-idwg-beep-idxp (context) - Feinstein, Matthews et al. - 2001
2
Distibuted audit trail analysis (context) - Mounji, Charlier et al. - 1995
2
Webster's New World Dictionary of Amercian English (context) - Neufeldt - 1988
The graph only includes citing articles where the year of publication is known.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC