A Basis for Intrusion Detection in Distributed Systems Using Kernel-level Data Tainting
Title | A Basis for Intrusion Detection in Distributed Systems Using Kernel-level Data Tainting PDF eBook |
Author | Christophe Hauser |
Publisher | |
Pages | 135 |
Release | 2013 |
Genre | |
ISBN |
Modern organisations rely intensively on information and communicationtechnology infrastructures. Such infrastructures offer a range of servicesfrom simple mail transport agents or blogs to complex e-commerce platforms,banking systems or service hosting, and all of these depend on distributedsystems. The security of these systems, with their increasing complexity, isa challenge. Cloud services are replacing traditional infrastructures byproviding lower cost alternatives for storage and computational power, butat the risk of relying on third party companies. This risk becomesparticularly critical when such services are used to host privileged companyinformation and applications, or customers' private information. Even in thecase where companies host their own information and applications, the adventof BYOD (Bring Your Own Device) leads to new security relatedissues.In response, our research investigated the characterization and detection ofmalicious activities at the operating system level and in distributedsystems composed of multiple hosts and services. We have shown thatintrusions in an operating system spawn abnormal information flows, and wedeveloped a model of dynamic information flow tracking, based on taintmarking techniques, in order to detect such abnormal behavior. We trackinformation flows between objects of the operating system (such as files,sockets, shared memory, processes, etc.) and network packetsflowing between hosts. This approach follows the anomaly detection paradigm.We specify the legal behavior of the system with respect to an informationflow policy, by stating how users and programs from groups of hosts areallowed to access or alter each other's information. Illegal informationflows are considered as intrusion symptoms. We have implemented this modelin the Linux kernel (the source code is availableat http://www.blare-ids.org), as a Linux Security Module (LSM), andwe used it as the basis for practical demonstrations. The experimentalresults validated the feasibility of our new intrusion detection principles.
Intrusion Detection in Distributed Systems
Title | Intrusion Detection in Distributed Systems PDF eBook |
Author | Peng Ning |
Publisher | Springer Science & Business Media |
Pages | 146 |
Release | 2012-12-06 |
Genre | Computers |
ISBN | 1461504678 |
Intrusion Detection In Distributed Systems: An Abstraction-Based Approach presents research contributions in three areas with respect to intrusion detection in distributed systems. The first contribution is an abstraction-based approach to addressing heterogeneity and autonomy of distributed environments. The second contribution is a formal framework for modeling requests among cooperative IDSs and its application to Common Intrusion Detection Framework (CIDF). The third contribution is a novel approach to coordinating different IDSs for distributed event correlation.
Support Vector Machines Applications
Title | Support Vector Machines Applications PDF eBook |
Author | Yunqian Ma |
Publisher | Springer Science & Business Media |
Pages | 306 |
Release | 2014-02-12 |
Genre | Technology & Engineering |
ISBN | 3319023004 |
Support vector machines (SVM) have both a solid mathematical background and practical applications. This book focuses on the recent advances and applications of the SVM, such as image processing, medical practice, computer vision, and pattern recognition, machine learning, applied statistics, and artificial intelligence. The aim of this book is to create a comprehensive source on support vector machine applications.
Botnet Detection
Title | Botnet Detection PDF eBook |
Author | Wenke Lee |
Publisher | Springer Science & Business Media |
Pages | 178 |
Release | 2007-10-23 |
Genre | Computers |
ISBN | 0387687688 |
Botnets have become the platform of choice for launching attacks and committing fraud on the Internet. A better understanding of Botnets will help to coordinate and develop new technologies to counter this serious security threat. Botnet Detection: Countering the Largest Security Threat consists of chapters contributed by world-class leaders in this field, from the June 2006 ARO workshop on Botnets. This edited volume represents the state-of-the-art in research on Botnets.
Android Malware
Title | Android Malware PDF eBook |
Author | Xuxian Jiang |
Publisher | Springer Science & Business Media |
Pages | 50 |
Release | 2013-06-13 |
Genre | Computers |
ISBN | 1461473942 |
Mobile devices, such as smart phones, have achieved computing and networking capabilities comparable to traditional personal computers. Their successful consumerization has also become a source of pain for adopting users and organizations. In particular, the widespread presence of information-stealing applications and other types of mobile malware raises substantial security and privacy concerns. Android Malware presents a systematic view on state-of-the-art mobile malware that targets the popular Android mobile platform. Covering key topics like the Android malware history, malware behavior and classification, as well as, possible defense techniques.
Handbook of Research on Intrusion Detection Systems
Title | Handbook of Research on Intrusion Detection Systems PDF eBook |
Author | Gupta, Brij B. |
Publisher | IGI Global |
Pages | 407 |
Release | 2020-02-07 |
Genre | Computers |
ISBN | 1799822435 |
Businesses in today’s world are adopting technology-enabled operating models that aim to improve growth, revenue, and identify emerging markets. However, most of these businesses are not suited to defend themselves from the cyber risks that come with these data-driven practices. To further prevent these threats, they need to have a complete understanding of modern network security solutions and the ability to manage, address, and respond to security breaches. The Handbook of Research on Intrusion Detection Systems provides emerging research exploring the theoretical and practical aspects of prominent and effective techniques used to detect and contain breaches within the fields of data science and cybersecurity. Featuring coverage on a broad range of topics such as botnet detection, cryptography, and access control models, this book is ideally designed for security analysts, scientists, researchers, programmers, developers, IT professionals, scholars, students, administrators, and faculty members seeking research on current advancements in network security technology.
Insider Attack and Cyber Security
Title | Insider Attack and Cyber Security PDF eBook |
Author | Salvatore J. Stolfo |
Publisher | Springer Science & Business Media |
Pages | 228 |
Release | 2008-08-29 |
Genre | Computers |
ISBN | 0387773223 |
This book defines the nature and scope of insider problems as viewed by the financial industry. This edited volume is based on the first workshop on Insider Attack and Cyber Security, IACS 2007. The workshop was a joint effort from the Information Security Departments of Columbia University and Dartmouth College. The book sets an agenda for an ongoing research initiative to solve one of the most vexing problems encountered in security, and a range of topics from critical IT infrastructure to insider threats. In some ways, the insider problem is the ultimate security problem.