COTS diversity based intrusion detection and application to web servers

Eric Totel, Frédéric Majorczyk, Ludovic Mé

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

It is commonly accepted that intrusion detection systems (IDS) are required to compensate for the insufficient security mechanisms that are available on computer systems and networks. However, the anomaly-based IDSes that have been proposed in the recent years present some drawbacks, e.g., the necessity to explicitly define a behaviour reference model. In this paper, we propose a new approach to anomaly detection, based on the design diversity, a technique from the dependability field that has been widely ignored in the intrusion detection area. The main advantage is that it provides an implicit, and complete reference model, instead of the explicit model usually required. For practical reasons, we actually use Components-off-the-shelf (COTS) diversity, and discuss on the impact of this choice. We present an architecture using COTS-diversity, and then apply it to web servers. We also provide experimental results that confirm the expected properties of the built IDS, and compare them with other IDSes.

Original languageEnglish
Title of host publicationRecent Advances in Intrusion Detection - 8th International Symposium, RAID 2005, Revised Papers
PublisherSpringer Verlag
Pages43-62
Number of pages20
ISBN (Electronic)9783540317784
ISBN (Print)3540317783, 9783540317784
DOIs
Publication statusPublished - 1 Jan 2006
Externally publishedYes
Event8th International Symposium on Recent Advances in Intrusion Detection, RAID 2005 - Seattle, WA, United States
Duration: 7 Sept 20059 Sept 2005

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume3858 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference8th International Symposium on Recent Advances in Intrusion Detection, RAID 2005
Country/TerritoryUnited States
CitySeattle, WA
Period7/09/059/09/05

Keywords

  • Anomaly detection
  • COTS diversity
  • Design diversity
  • Intrusion detection

Fingerprint

Dive into the research topics of 'COTS diversity based intrusion detection and application to web servers'. Together they form a unique fingerprint.

Cite this