Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Storage-based Intrusion Detection: Watching Storage Activity for Suspicious Behavior

Storage-based intrusion detection allows storage systems to watch for data modifications characteristic of system intrusions. This enables storage systems to spot several common intruder actions, such as adding backdoors, inserting Trojan horses, and tampering with audit logs. Further, an intrusion detection system (IDS) embedded in a storage device continues to operate even after client systems are compromised. This paper describes a number of specific warning signs visible at the storage interface. Examination of 18 real intrusion tools reveals that most (15) can be detected based on their changes to stored files. We describe and evaluate a prototype storage IDS, embedded in an NFS server, to demonstrate both feasibility and efficiency of storage-based intrusion detection. In particular, both the performance overhead and memory required (152 KB for 4730 rules) are minimal.

Adam G. Pennington, Carnegie Mellon University

John D. Strunk, Carnegie Mellon University

John Linwood Griffin, Carnegie Mellon University

Craig A.N. Soules, Carnegie Mellon University

Garth R. Goodson, Carnegie Mellon University

Gregory R. Ganger, Carnegie Mellon University

BibTeX
@inproceedings {270158,
author = {Adam G. Pennington and John D. Strunk and John Linwood Griffin and Craig A.N. Soules and Garth R. Goodson and Gregory R. Ganger},
title = {Storage-based Intrusion Detection: Watching Storage Activity for Suspicious Behavior},
booktitle = {12th USENIX Security Symposium (USENIX Security 03)},
year = {2003},
address = {Washington, D.C.},
url = {https://www.usenix.org/conference/12th-usenix-security-symposium/storage-based-intrusion-detection-watching-storage},
publisher = {USENIX Association},
month = aug
}
Download

Links

Paper: 
http://www.usenix.org/events/sec03/tech/full_papers/pennington/pennington.pdf
Paper (HTML): 
http://www.usenix.org/events/sec03/tech/full_papers/pennington/pennington_html/
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us