White Papers

Dependency-Based Distributed Intrusion Detection

Category: Security

Tags: network

Overview Distributed network intrusion detection has attracted much attention recently. The main focus in this work is on zero-day, slow-scanning worms, of which no existing signatures are available. End hosts are organized into regions based on network knowledge, which it posits is positively correlated to the dependency structure. Leveraging on this organization, different intrusion detection techniques are applied within and across regions. A Hidden Markov Model (HMM) is used within a region to capture the dependency among hosts, and use Sequential Hypothesis Testing (SHT) globally to take advantage of the independence between regions.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Massachusetts Institute of Technology
File Format
PDF
Date Published
Apr 11, 2008
Format
White Papers
Topics
Intrusion Detection Systems, Security Tools

Similiar White Papers

Web Application Security: Automated scanning versus manual penetration testing

Web Application Security: Automated scanning versus manual penetration testing

Research has shown that a vast number of Web sites are vulnerable to application attacks, most occurring over HTTP/S pro

Publisher: IBM  |  Tags: penetration testing

A Neural Network Based System for Intrusion Detection and Classification of Attacks

A Neural Network Based System for Intrusion Detection and Classification of Attacks

With the rapid expansion of computer networks during the past decade, security has become a crucial issue for computer s

Publisher: Queen's University  |  Tags: network

Security: New strides in preventing intrusions.

Security: New strides in preventing intrusions.

Need help eliminating risk in your IT environment? This ForwardView webshow describes how security appliances, which inc

Publisher: IBM

ATLANTIDES: An Architecture for Alert Verification in Network Intrusion Detection Systems

ATLANTIDES: An Architecture for Alert Verification in Network Intrusion Detection Systems

This paper presents an architecture1 designed for alert verification (i.e., to reduce false positives) in network intrus

Publisher: University of Twente  |  Tags: false positives, network, server

Using Artificial Intelligence in Intrusion Detection Systems

Using Artificial Intelligence in Intrusion Detection Systems

Artificial Intelligence could make the use of Intrusion Detection Systems a lot easier than it is today. They could lear

Publisher: Helsinki University of Technology

Massachusetts Institute of Technology White Papers

Facemail: Showing Faces of Recipients to Prevent Misdirected Email

Facemail: Showing Faces of Recipients to Prevent Misdirected Email

Users occasionally send email to the wrong recipients - clicking Reply To All instead of Reply, mistyping an email addre

Publisher: Massachusetts Institute of Technology  |  Tags: data, email, webmail

The Power Line Transmission Characteristics for an OFDM Signal

The Power Line Transmission Characteristics for an OFDM Signal

This paper measures what influence the sinusoidal transmission characteristics of the electric power line with various f

Publisher: Massachusetts Institute of Technology  |  Tags: data

Energy Efficient Connected Clusters for Mobile Ad Hoc Networks

Energy Efficient Connected Clusters for Mobile Ad Hoc Networks

A Mobile Ad hoc NETwork (MANET) is a wireless infrastuctureless network with mobile nodes. Clustering is a common basis

Publisher: Massachusetts Institute of Technology  |  Tags: applications, network

WebTorrent: A BitTorrent Extension for High Availability Servers

WebTorrent: A BitTorrent Extension for High Availability Servers

Achieving content high-availability is one of the most important goals of a webserver system. In order to achieve high-a

Publisher: Massachusetts Institute of Technology  |  Tags: bittorrent, server

High Availability in DHTs: Erasure Coding Vs. Replication

High Availability in DHTs: Erasure Coding Vs. Replication

High availability in peer-to-peer DHTs requires data redundancy. This paper compares two popular redundancy schemes: rep

Publisher: Massachusetts Institute of Technology  |  Tags: data, peer-to-peer