• DocumentCode
    3370494
  • Title

    IDEA: A New Intrusion Detection Data Source

  • Author

    Mahoney, William ; Sousan, William

  • Author_Institution
    Univ. of Nebraska at Omaha, Omaha
  • fYear
    2008
  • fDate
    24-26 April 2008
  • Firstpage
    15
  • Lastpage
    19
  • Abstract
    In the context of computer systems, an intrusion is generally considered to be a harmful endeavor to prevent others from legitimate use of that system, to obtain data which is not normally available to the intruder, or to plant data or disrupt data already existent on the machines. Traditionally intrusion detection has relied on two data sources: various log files which record user´s activity, and network traffic which contains potential threats. This research presents a system which we call IDEA; the Intrusion DEtection Automata system. We utilize a third source of data for intrusion detection in the form of an instrumented process. Open source software is recompiled using a modified compiler we have created, and the resulting executable program generates the data as it runs. An external monitoring facility then checks the behavior of the program against known good execution paths. These paths are specified either using a domain specific language and hand-written rules, or by running the software in a learning mode and capturing the normal behavior for later comparison.
  • Keywords
    security of data; computer systems; data source; intrusion detection automata system; network traffic; Automata; Computerized monitoring; DSL; Domain specific languages; Information security; Instruments; Intrusion detection; Open source software; Operating systems; Telecommunication traffic; instrumentation; intrusion detection; open-source;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security and Assurance, 2008. ISA 2008. International Conference on
  • Conference_Location
    Busan
  • Print_ISBN
    978-0-7695-3126-7
  • Type

    conf

  • DOI
    10.1109/ISA.2008.32
  • Filename
    4511526