FREE Registration is required
Overview:
This study develops a method to build Finite State Automaton (FSA) that models the dependencies between the Operating-System (OS)-level events recorded in the audit logs of a Windows NT machine. The FSA model contains both sequential and branching relations among audit log events that help the system administrator follow the steps of the intruder. Audit-Log-FSA (ALFSA) are relatively proportional to the size of the audit log, hence, may have too many states and transitions. The Superset-Intrusion-Signature-FSA (SISFSA) is extracted using formal methods on ALFSA. The SISFSA accepts a super set of the intruder's steps since not all of its actions may result in system failure, yet it provides the system administrator with a smaller set of patterns compared to ALFSA.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Size: | 275 KB | |
| Date: | May 2008 | ||
| Pages: | 9 |
Top results from Network Security
» View all Network Security listings
Top results from Intrusion Detection Systems
White Papers, Webcasts, and Resources
- Red Hat support, patches, updates with the interoperability of Novell NovellGet top-ranked Novell support for your Existing Red Hat Environment
- The Essential Guide: Real-Time High Availability for Exchange - Replicate Exchange Data for Improved Resiliency CA XOsoftSurvive major interruptions to your Exchange environment--and improve its resiliency and availability--with a real-time data replication solution.
- Is Your Security Effective? The Value of Application Security Testing Tools Ounce LabsDiscover why you need strong application security testing tools, what these tools should include, and how to select the best solution for your needs.
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- News, Insights, Guidance
Visit CBSMoneyWatch.com Today -
MoneyWatch.com is the premier destination for smart, practical personal finance advice. Watch the latest Human Capital videos to make the most of your biggest asset - your earning power
- Learn more >>
Featured Training Courses
Meet Doc
-
Here to help you with your Document Management Needs
- Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
- To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
-
Produced by
ZDNet and







