usenix conference policies
Experience with EMERALD Thus Far
Abstract:
After summarizing the EMERALD architecture and the evolutionary process from which EMERALD has evolved, this paper focuses on our experience to date in designing, implementing, and applying EMERALD to various types of anomalies and misuse. The discussion addresses the fundamental importance of good software engineering practice and the importance of the system architecture - in attaining detectability, interoperability, general applicability, and future evolvability. It also considers the importance of correlation among distributed and hierarchical instances of EMERALD, and needs for additional detection and analysis components.
BibTeX
@inproceedings {271738,
author = {Phillip A. Porras and Peter G. Neumann and Teresa Lunt},
title = {Experience with {EMERALD} Thus Far},
booktitle = {1st Workshop on Intrusion Detection and Network Monitoring (ID 99)},
year = {1999},
address = {Santa Clara, CA},
url = {https://www.usenix.org/conference/id-99/experience-emerald-thus-far},
publisher = {USENIX Association},
month = apr
}
author = {Phillip A. Porras and Peter G. Neumann and Teresa Lunt},
title = {Experience with {EMERALD} Thus Far},
booktitle = {1st Workshop on Intrusion Detection and Network Monitoring (ID 99)},
year = {1999},
address = {Santa Clara, CA},
url = {https://www.usenix.org/conference/id-99/experience-emerald-thus-far},
publisher = {USENIX Association},
month = apr
}
connect with us