Network Security White Papers
Efficient Intrusion Detection Using Automaton Inlining
Overview Host-based intrusion detection systems attempt to identify attacks by discovering program behaviors that deviate from expected patterns. While the idea of performing behavior validation on-the-fly and terminating errant tasks as soon as a violation is detected is appealing, existing systems exhibit serious shortcomings in terms of accuracy and/or efficiency. To gain acceptance, a number of technical advances are needed. This paper focuses on automated, conservative, intrusion detection techniques, i.e. techniques which do not require human intervention and do not suffer from false positives. It presents a static analysis algorithm for constructing a flow- and context-sensitive model of a program that allows for efficient online validation.
| Publisher | Purdue University | File Format | |
|---|---|---|---|
| Date Published | February 2005 | ||
| Format | White Papers | ||
| Topics | |||



