An Improved Intrusion Detecting Method Based on Process Profiling(<Special Issue>Special Issue on Selected Papers from SAINT 2002(The 2002 Symposium on Applications and the Internet))
スポンサーリンク
概要
- 論文の詳細を見る
There have been two well-known models for host based intrusion detection. They are called Anomaly Intrusion Detection (AID) model and Misuse Intrusion Detection (MID) model. The former model analyzes user behavior and the statistics of a process in normal situation, and it checks whether the system is being used in a different manner. The latter model maintains database of known intrusion technique and detects intrusion by comparing a behavior against the database. An intrusion detection method based on an AID model can detect a new intrusion method, however it needs to update the data describing users behavior and the statistics in normal usage. We call these information profiles. There are several problems in AID to be addressed. The profiles are tend to be large. Detecting intrusion needs a large amount of system resource, like CPU time and memory and disk space. An MID model requires less amount of system resource to detect intrusion. However it cannot detect new,unknown intrusion methods. Our method solves these problems by recording system calls from daemon processes and setuid programs. We have further improved the method to eliminate false positive intrusion detections by adopting a DP matching scheme.
- 2002-11-15
著者
-
Goto S
Waseda Univ. Tokyo Jpn
-
Sato I
Waseda University
-
SATO IZURU
Waseda University
-
OKAZAKI YOSHINORI
Matsushita Electric Industrial Co., Ltd.
-
GOTO SHIGEKI
Waseda University
-
Okazaki Yoshinori
Matsushita Electric Industrial Co. Ltd.
関連論文
- An Improved Intrusion Detecting Method Based on Process Profiling(Special Issue on Selected Papers from SAINT 2002(The 2002 Symposium on Applications and the Internet))
- Public Information Server for Tracing Intruders in the Internet(Special Issue on Network Software)
- A New Intrusion Detection Method Based on Discriminant Analysis (Special Issue on High-speed Internet Technology and its Applications)
- Local Attack Detection and Intrusion Route Tracing (Special Issue on New Paradigms in Network Management)