Passer à la navigation principale Passer à la recherche Passer au contenu principal

Anomaly detection with diagnosis in diversified systems using information flow graphs

  • Frédéric Majorczyk
  • , Eric Totel
  • , Ludovic Mé
  • , Ayda Saïdane
  • Supelec
  • Università di Trento

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

6 Citations (Scopus)

Résumé

Design diversity is a well-known method to ensure fault tolerance. Such a method has also been applied successfully in various projects to provide intrusion detection and tolerance. Two types of approaches have been investigated: the comparison of the outputs of the diversified services without any knowledge of the internals of the server (black box approach) or an intrusive observation of the activities that occur on the diversified servers (gray box approach). Previous work on black-box approaches have shown that some types of attacks cannot be detected. In this paper, we introduce a gray-box approach, on the one hand to increase the detection coverage, and on the other hand to add some diagnosis capability to the IDS. Our gray-box approach is based on the comparison of information flow graphs generated by the activities on the servers.

langue originaleAnglais
titreProceedings of The Ifip Tc 11 23rd International Information Security Conference
Sous-titreIFIP 20th World Computer Congress, IFIP SEC'08
EditeurSpringer New York
Pages301-315
Nombre de pages15
ISBN (imprimé)9780387096988
Les DOIs
étatPublié - 1 janv. 2008
Modification externeOui

Série de publications

NomIFIP International Federation for Information Processing
Volume278
ISSN (imprimé)1571-5736

Empreinte digitale

Examiner les sujets de recherche de « Anomaly detection with diagnosis in diversified systems using information flow graphs ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation