Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Network-based Intrusion Detection–Modeling for a Larger Picture

The Internet is changing computing more than ever before. As the possibilities and the scopes are limitless, so too are the risks and chances of malicious intrusions. Due to the increased connectivity and the vast spectrum of financial possibilities, more and more systems are subject to attack by intruders. One of the commonly used method for intrusion detection is based on anomaly. Network based attacks may occur at various levels, from application to link levels. So the number of potential attackers or intruders are extremely large and thus it is almost impossible to ``profile'' entities and detect intrusions based on anomalies in host-based profiles. Based on meta-information, logical groupings has been made for the alerts that belongs to same logical network, to get a clearer and boarder view of the perpetrators. To reduce the effect of probably insignificant alerts a threshold technique is used.

Atsushi Totsuka, Tohoku University

Hidenari Ohwada, NTT, Tokyo

Nobuhisa Fujita, Tohoku University

Debasish Chakraborty, Tohoku University

Glenn Mansfield Keeni, Cyber Solutions, Inc.

Norio Shiratori, Tohoku University

BibTeX
@inproceedings {270494,
author = {Atsushi Totsuka and Hidenari Ohwada and Nobuhisa Fujita and Debasish Chakraborty and Glenn Mansfield Keeni and Norio Shiratori},
title = {Network-based Intrusion {Detection{\textendash}Modeling} for a Larger Picture},
booktitle = {16th Systems Administration Conference (LISA 02)},
year = {2002},
address = {Philadelphia, PA},
url = {https://www.usenix.org/conference/lisa-02/network-based-intrusion-detection{\textendash}modeling-larger-picture},
publisher = {USENIX Association},
month = nov
}
Download

Links

Paper: 
http://usenix.org/publications/library/proceedings/lisa02/tech/full_papers/totsuka/totsuka.pdf
Paper (HTML): 
http://usenix.org/publications/library/proceedings/lisa02/tech/full_papers/totsuka/totsuka_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

LISA is a registered trademark of the USENIX Association.

  • Privacy Policy
  • Contact Us