Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

The DIDS (Distributed Intrusion Detection System) Prototype

Steven R. Snapp and Stephen E. Smaha, Haystack Laboratories, Inc.; Daniel M. Teal and Tim Grance, United States Air Force Cryptologic Support Center

Intrusion detection is the problem of identifying unauthorized use, misuse, and abuse of computer systems by both system insiders and external penetrators. The growth in numbers and complexity of heterogeneous computer networks provides additional implications for the intrusion detection problem. In particular, the increased connectivity of computer systems gives greater access to outsiders, and makes it easier for intruders to avoid detection. We are designing and implementing a prototype Distributed Intrusion Detection System (DIDS) that combines distributed monitoring and data reduction (through individual Host and LAN Monitors) with centralized data analysis (through the DIDS Director) in order to monitor a heterogeneous network of computers. This approach is unique among current intrusion detection systems. One of the problems considered in this paper is the Network-user Identification (NID) problem, which is concerned with tracking a user moving across the network, possibly with a new user-id on each computer. Initial system prototypes have provided quite favorable results on both the NID problem and the detection of other attacks on a network. This paper provides an overview of the motivation behind DIDS, the system architecture and capabilities, and a discussion about the implementation of the system prototype

Steven R. Snapp, Haystack Laboratories, Inc.;

Stephen E. Smaha, Haystack Laboratories, Inc.;

Daniel M. Teal, United States Air Force Cryptologic Support Center

Tim Grance, United States Air Force Cryptologic Support Center

BibTeX
@inproceedings {252401,
author = {Steven R. Snapp and Stephen E. Smaha and Daniel M. Teal and Tim Grance},
title = {The {DIDS} (Distributed Intrusion Detection System) Prototype},
booktitle = {USENIX Summer 1992 Technical Conference (USENIX Summer 1992 Technical Conference)},
year = {1992},
address = {San Antonio, TX},
url = {https://www.usenix.org/conference/usenix-summer-1992-technical-conference/dids-distributed-intrusion-detection-system},
publisher = {USENIX Association},
month = jun
}
Download

Links

Paper: 
http://usenix.org/publications/library/proceedings/sa92/snapp.pdf
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us