Abstract:
Drawing from the experience obtained during the development and testing of a distributed intrusion detection system, we reflect on the data collection needs of intrusion detection systems, and on the limitations that are faced when using the data collection mechanisms built into most operating systems. We claim that it is best for an intrusion detection system to be able to collect its data by looking directly at the operations of the host, instead of indirectly through audit trails or network packets. Furthermore, for collecting data in an ecient, reliable and complete fashion, incorporation of monitoring mechanisms in the source code of the operating system and its applications is needed.
Citations
|
294
|
An intrusion-detection model
– Denning
- 1987
|
|
193
|
Insertion, evasion, and denial of service: Eluding network intrusion detection
– Ptacek, Newsham
- 1998
|
|
179
|
Network intrusion detection
– Mukherjee, Heberlein, et al.
- 1994
|
|
115
|
An Architecture for Intrusion Detection using Autonomous Agents
– Balasubramaniyan, Garcia-Fernandez, et al.
- 1998
|
|
58
|
A software architecture to support misuse intrusion detection
– Kumar, ord
- 1995
|
|
53
|
TCP wrapper: Network monitoring, access control and booby traps
– Venema
- 1992
|
|
33
|
Languages and Tools for Rule-Based Distributed Intrusion Detection, Facult es Universitaires Notre-Dame de la Paix
– Mounji
- 1997
|
|
12
|
Host-based misuse detection and conventional operating systems' audit data collection
– Price
- 1997
|
|
9
|
Generation of Application Level Audit Data via Library Interposition
– Kuperman, Spafford
- 1999
|
|
6
|
page at http://www.openbsd.org
– Web
|
|
3
|
Network attack sensing. Unpublished technical report
– Kerschbaum
- 2000
|
|
2
|
Requirements and Model for IDES { A Real-Time In5 trusion Detection System
– Denning, Neumann
- 1985
|