Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Intrusion Detection Through Dynamic Software Measurement

The thrust of this paper is to present a new real-time approach to detect aberrant modes of system behavior induced by abnormal and unauthorized system activities. The theoretical foundation for the research program is based on the study of the software internal behavior. As a software system is executing, it will express a set of its many functionalities as sequential events. Each of these functionalities has a characteristic set of modules that it will execute. In addition, these module sets will execute with clearly defined and measurable execution profiles. These profiles change as the executed functionalities change. Over time, the normal behavior of the system will be defined by profiles. An attempt to violate the security of the system will result in behavior that is outside the normal activity of the system and thus result in a perturbation in the normal profiles. We will show, through the real-time analysis of the Linux kernel, that we can detect very subtle shifts in the behavior of a system.

Sebastian Elbaum, University of Idaho

John C. Munson, University of Idaho

BibTeX
@inproceedings {271742,
author = {Sebastian Elbaum and John C. Munson},
title = {Intrusion Detection Through Dynamic Software Measurement},
booktitle = {1st Workshop on Intrusion Detection and Network Monitoring (ID 99)},
year = {1999},
address = {Santa Clara, CA},
url = {https://www.usenix.org/conference/id-99/intrusion-detection-through-dynamic-software-measurement},
publisher = {USENIX Association},
month = apr
}
Download

Links

Paper: 
http://www.usenix.org/publications/library/proceedings/detection99/full_papers/elbaum/elbaum.pdf
Paper (HTML): 
http://www.usenix.org/publications/library/proceedings/detection99/full_papers/elbaum/elbaum_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us