A serial combination of anomaly and misuse IDSes applied to HTTP traffic

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Combining an "anomaly" and a "misuse" IDSes offers the advantage of separating the monitored events between normal, intrusive or unqualified classes (ie not known as an attack, but not recognize as safe either). In this article, we provide a framework to systematically reason about the combination of anomaly and misuse components. This framework applied to web servers lead us to propose a serial architecture, using a drastic anomaly component with a sensitive misuse component. This architecture provides the operator with better qualification of the detection results, raises lower amount of false alarms and unqualified events.

Original languageEnglish
Title of host publicationProceedings - 20th Annual Computer Security Applications Conference, ACSAC 2004
Pages428-437
Number of pages10
DOIs
Publication statusPublished - 1 Dec 2004
Externally publishedYes
Event20th Annual Computer Security Applications Conference, ACSAC 2004 - Tucson, AZ, United States
Duration: 6 Dec 200410 Dec 2004

Publication series

NameProceedings - Annual Computer Security Applications Conference, ACSAC
ISSN (Print)1063-9527

Conference

Conference20th Annual Computer Security Applications Conference, ACSAC 2004
Country/TerritoryUnited States
CityTucson, AZ
Period6/12/0410/12/04

Fingerprint

Dive into the research topics of 'A serial combination of anomaly and misuse IDSes applied to HTTP traffic'. Together they form a unique fingerprint.

Cite this