White Papers
BINDER: An Extrusion-Based Break-In Detector for Personal Computers
Overview This paper tackles the problem of automated detection of break-ins of new unknown threats such as worms, spyware and adware on personal computers. It proposes Break-IN DE-tectoR (BINDER), a host-based system that detects break-ins by capturing extrusions, stealthy malicious outgoing network traffic sent by them. To capture extrusions, BINDER correlates outgoing network traffic and process information with user activity. This is a unique characteristic of personal computers in contrast to server computers. Since threats tend to run as background processes and thus do not receive any user input, the intuition behind BINDER is that only processes that receive user input are allowed to make connections.
| Publisher | University of California | File Format | |
|---|---|---|---|
| Date Published | October 2004 | ||
| Format | White Papers | ||
| Topics |
|
||


