Passer à la navigation principale Passer à la recherche Passer au contenu principal

Building an application data behavior model for intrusion detection

  • Supelec

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

2 Citations (Scopus)

Résumé

Application level intrusion detection systems usually rely on the immunological approach. In this approach, the application behavior is compared at runtime with a previously learned application profile of the sequence of system calls it is allowed to emit. Unfortunately, this approach cannot detect anything but control flow violation and thus remains helpless in detecting the attacks that aim pure application data. In this paper, we propose an approach that would enhance the detection of such attacks. Our proposal relies on a data oriented behavioral model that builds the application profile out of dynamically extracted invariant constraints on the application data items.

langue originaleAnglais
titreData and Applications Security XXIII - 23rd Annual IFIP WG 11.3 Working Conference, Proceedings
Pages299-306
Nombre de pages8
Les DOIs
étatPublié - 2 nov. 2009
Modification externeOui
Evénement23rd Annual IFIP WG 11.3 Working Conference on Data and Applications Security - Montreal, QC, Canada
Durée: 12 juil. 200915 juil. 2009

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume5645 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence23rd Annual IFIP WG 11.3 Working Conference on Data and Applications Security
Pays/TerritoireCanada
La villeMontreal, QC
période12/07/0915/07/09

Empreinte digitale

Examiner les sujets de recherche de « Building an application data behavior model for intrusion detection ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation