FREE Registration is required
Overview:
Current intrusion detection systems point out suspicious states or events but do not show how the suspicious state or events relate to other states or events in the system. This paper shows how to enrich an IDS alert with information about how those alerts causally lead to or result from other events in the system. By enriching IDS alerts with this type of causal information, one can leverage existing IDS alerts to learn more about the suspected attack. Backward causal graphs can be used to find which host allowed a multi-hop attack (such as a worm) to enter a local network; forward causal graphs can be used to find the other hosts that were affected by the multi-hop attack.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Size: | 213 KB | |
| Date: | Jan 2008 | ||
| Pages: | 12 |
Top results from Intrusion Detection Systems
» View all Intrusion Detection Systems listings
Top results from Network Security
White Papers, Webcasts, and Resources
- Live Webcast: Enhanced Availability in a Virtual Data Center with the Dell PS Series and Microsoft Windows Server 2008 R2 Hyper-V Dell EqualLogicLearn how to use the new features of Microsoft Windows Server 2008 R2 Hyper-V to boost the availability of your virtualized data center.
- Live Webcast: Get Control over SaaS Application Access TriCipherLearn to simplify and protect access to your company's data in Software-as-a-Service (SaaS) apps using identity and access management best practices.
- Live Event - Increasing Energy Efficiency with x86 Servers IBMLooking to save on data center operations? Maximize energy efficiency by consolidating your distributed x86-based computers onto fewer machines.











