Network Security White Papers

Going Beyond Behavior-Based Intrusion Detection

Overview Today's Intrusion Detection (ID) ideas focus on two solutions: detecting intrusions based on known vulnerabilities and detecting anomalies in the normal "Behavior" in a particular system, be it the network or the host. Although not immune from false-positives or true-negatives, these systems do a lot for ID, but the damage from unknown attacks is more substantial as people deploy these systems and let their guards down. This paper attempts to see if a guarantee of security can be asserted in two popular ID areas: Host-Based ID and Denial of Service ID on the network.

Further White Paper Details
PublisherBinghamton University File FormatPDF
Date PublishedDecember 2003
FormatWhite Papers   
Topics

Quick Sitemap Links: