System and methods for adaptive model generation for detecting intrusion in computer systems

作者: Eleazar Eskin , Salvatore J. Stolfo , Andrew Honig , Andrew Howard

DOI:

关键词: Intrusion detection systemData processingDatabaseData formatData warehouseReal-time computingDetectorData recordsIntrusionComputer scienceGenerator (computer programming)

摘要: A system and methods for detecting intrusions in the operation of a computer comprises sensor configured to gather information regarding system, format data record having predetermined format, transmit format. warehouse is receive from store SQL database. detection model generator request records generate an intrusion based on said records, according detector classify real-time as one normal attack model. analysis engine perform processing function records.

参考文章(335)
David M. Chess, John F. Morar, William C. Arnold, Steve R. White, Morton Swimmer, Edward J. Pring, Anatomy of a Commercial-Grade Immune System ,(1999)
Nong Ye, A Markov Chain Model of Temporal Behavior for Anomaly Detection information assurance and security. ,(2000)
Aaron Schwartzbard, Anup K. Ghosh, A Study in the Feasibility of Performing Host-Based Anomaly Detection on Windows NT. recent advances in intrusion detection. ,(1999)
James D. Murray, Windows NT Event Logging ,(1998)
Debra Anderson, Thane Frivold, Alfonso Valdes, Next-generation Intrusion Detection Expert System (NIDES)A Summary ,(1997)
Salvatore J. Stolfo, Wei Fan, Ensemble-based Adaptive Intrusion Detection. siam international conference on data mining. pp. 41- 58 ,(2002)