White Papers

Characterizing Intrusion Tolerant Systems Using a State Transition Model

Category: Security

Overview Intrusion detection and response research has so far mostly concentrated on known and well-defined attacks. The authors believe that this narrow focus of attacks accounts for both the successes and limitation of commercial in Intrusion Detection Systems (IDS). Intrusion tolerance, on the other hand, is inherently tied to functions and services that require protection. This paper presents a state transition model to describe the dynamic behavior of intrusion tolerant systems. This model provides a framework from which one can define the vulnerability and the threat set to be addressed. The authors also show how this model helps one to describe both known and unknown security exploits by focusing on impacts rather than specific attack procedures.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Duke University
File Format
PDF
Date Published
Apr 11, 2008
Format
White Papers
Topics
Intrusion Detection Systems, Security Tools

Similiar White Papers

Web Application Security: Automated scanning versus manual penetration testing

Web Application Security: Automated scanning versus manual penetration testing

Research has shown that a vast number of Web sites are vulnerable to application attacks, most occurring over HTTP/S pro

Publisher: IBM  |  Tags: penetration testing

A Neural Network Based System for Intrusion Detection and Classification of Attacks

A Neural Network Based System for Intrusion Detection and Classification of Attacks

With the rapid expansion of computer networks during the past decade, security has become a crucial issue for computer s

Publisher: Queen's University  |  Tags: network

Security: New strides in preventing intrusions.

Security: New strides in preventing intrusions.

Need help eliminating risk in your IT environment? This ForwardView webshow describes how security appliances, which inc

Publisher: IBM

ATLANTIDES: An Architecture for Alert Verification in Network Intrusion Detection Systems

ATLANTIDES: An Architecture for Alert Verification in Network Intrusion Detection Systems

This paper presents an architecture1 designed for alert verification (i.e., to reduce false positives) in network intrus

Publisher: University of Twente  |  Tags: false positives, network, server

Using Artificial Intelligence in Intrusion Detection Systems

Using Artificial Intelligence in Intrusion Detection Systems

Artificial Intelligence could make the use of Intrusion Detection Systems a lot easier than it is today. They could lear

Publisher: Helsinki University of Technology

Duke University White Papers

Data Center Workload Monitoring, Analysis, and Emulation

Data Center Workload Monitoring, Analysis, and Emulation

Over the last ten years the author has witnessed a shift from large mainframe computing to commodity, off-the-shelf clus

Publisher: Duke University  |  Tags: computing, data, management, server

Structure and Performance of the Direct Access File System

Structure and Performance of the Direct Access File System

The Direct Access File System (DAFS) is an emerging industrial standard for network-attached storage. DAFS takes advanta

Publisher: Duke University  |  Tags: applications, data, kernel, network

MobiNet: A Scalable Emulation Infrastructure for Ad Hoc and Wireless Networks

MobiNet: A Scalable Emulation Infrastructure for Ad Hoc and Wireless Networks

The current state of the art in evaluating applications and communication protocols for ad hoc wireless networks usually

Publisher: Duke University  |  Tags: applications, network, wireless networks

Scalability and Accuracy in a Large-Scale Network Emulator

Scalability and Accuracy in a Large-Scale Network Emulator

This paper presents ModelNet, a scalable Internet emulation environment that enables researchers to deploy unmodified so

Publisher: Duke University  |  Tags: network, os, software

Using Random Subsets to Build Scalable Network Services

Using Random Subsets to Build Scalable Network Services

This paper argues that a broad range of large-scale network services would benefit from a scalable mechanism for deliver

Publisher: Duke University  |  Tags: network, peer-to-peer