漂浮 发表于 2025-3-25 03:56:49
Undermining an Anomaly-Based Intrusion Detection System Using Common Exploitssses of an anomaly-based intrusion detector, and shows how an attacker can manipulate common attacks to exploit those weaknesses. The paper explores the implications of this threat, and suggests possible improvements for existing and future anomaly-based intrusion detection systems.BRIBE 发表于 2025-3-25 09:01:55
A Mission-Impact-Based Approach to INFOSEC Alarm Correlationact Intrusion Report Correlation System, or M-Correlator. M-Correlator is intended to provide analysts (at all experience levels) a powerful capability to automatically fuse together and isolate those INFOSEC alerts that represent the greatest threat to the health and security of their networks.Interim 发表于 2025-3-25 12:41:34
M2D2: A Formal Data Model for IDS Alert Correlationsly specified using the formal definition of M2D2. As opposed to already published correlation methods, these examples use more than the events generated by security tools; they make use of many concepts formalized in M2D2.密码 发表于 2025-3-25 16:54:01
http://reply.papertrans.cn/83/8229/822811/822811_24.pngPlatelet 发表于 2025-3-25 23:01:41
http://reply.papertrans.cn/83/8229/822811/822811_25.png弄脏 发表于 2025-3-26 00:08:02
Performance Adaptation in Real-Time Intrusion Detection Systems and cost-benefit analysis. The back-end performs scenario (or trend) analysis to recognize on-going attack sequences, so that the predictions of the likely . attacks can be used to pro-actively and optimally configure the IDS.Gobble 发表于 2025-3-26 06:54:57
Detecting Malicious Software by Monitoring Anomalous Windows Registry Accessesdel is used to check each access to the registry in real time to determine whether or not the behavior is abnormal and (possibly) corresponds to an attack. The system is effective in detecting the actions of malicious software while maintaining a low rate of false alarms泄露 发表于 2025-3-26 10:35:46
Introducing Reference Flow Control for Detecting Intrusion Symptoms at the OS Leveluence of another, in order to detect that kind of attacks. We propose a proof-of-concept application to a Unix system and show its ability to detect novel attack scenarii that seek the same intrusion goals.玛瑙 发表于 2025-3-26 14:07:11
Detecting Long Connection Chains of Interactive Terminal Sessionsgy for detecting suspicious remote sessions, used as part of a long connection chain. Interactive terminal sessions behave differently on long chains than on direct connections. The time gap between a client request and the server delayed acknowledgment estimates the round-trip time to the nearest s联合 发表于 2025-3-26 19:35:12
Multiscale Stepping-Stone Detection: Detecting Pairs of Jittered Interactive Streams by Exploiting Mre is a growing literature on ways to detect that an interactive connection into a site and another outbound from the site give evidence of such a “stepping stone.” This has been done based on monitoring the access link connecting the site to the Internet (Eg. [.,., .]). The earliest work was based