Linux - Open Source White Papers

Anomaly Detection Using Self/Nonself Discrimination for the Linux Kernel

Overview This paper discusses how computers can protect themselves from different forms of attacks, mis-configurations, and program errors. The work is inspired by the immune system and in a similar vein to the immune system the system learns how to distinguish self from nonself. The system is implemented as a couple of modules to the Linux kernel and analyses each system call of the monitored processes. To build and analyse profiles of the system calls it have implemented three different methods; a table lookup method, a feed-forward neural network, and an Elman recurrent neural network. Experiments show that this system can detect several methods of intrusion including buffer overflow attacks, format string exploits, and Trojan code.

Further White Paper Details
PublisherAbstract Void Computing File FormatPDF
Date PublishedJune 2003
FormatWhite Papers   
Topics
E4 embraces web 2.0 audience

E4 embraces web 2.0 audience

Case study: How the Channel 4's teen channel put its mind to building a community website... more

Cheat Sheet: Cloud computing

Cheat Sheet: Cloud computing

A tech storm is brewing...  more


Quick Sitemap Links: