Knowledge-based intrusion detection

Teresa F. Lunt, Raj Jagannathan, R. Lee, A. Whitehurst, S. Listgarten · 2003

The authors describe the expert-system aspects of IDES (intrusion-detection expert system). A system for computer intrusion detection IDES uses two distinct approaches to detect anomalies (which could signify intrusions) in a computer system, namely, statistical and rule-based anomaly detection. In the statistical approach, recent behavior of a subject of a computer system is compared with observed behavior and any significant deviation is considered anomalous. In the rule-based approach, acceptable behaviour of a subject is captured by a set of rules which is used to identify anomalous observed behavior. The authors claim that integrating the two approaches in IDES provides for a comprehensive system for detecting intrusions as they occur.>

Read the paper · More papers on PaperTik