On preventing intrusions by process behavior monitoring

Ramnath Sekar, Thomas F. Bowen, Mark E. Segal · 1999

Society's increasing reliance on networked information systems to support critical infrastructures has prompted interest in making the information systems survivable, so that they continue to perform critical functions even in the presence of vulnerabilities susceptible to malicious attacks. To enable vulnerable systems to survive attacks, it is necessary to detect attacks and isolate failures resulting from attacks before they damage the system by impacting functionality, performance or security. The key research problems in this context include: . detecting in-progress attacks before they cause damage, as opposed to detecting attacks after they have succeeded, . localizing and/or minimizing damage by isolating attacked components in real-time, and . tracing the origin of attacks.

Read the paper · More papers on PaperTik