首页    期刊浏览 2024年10月06日 星期日
登录注册

文章基本信息

  • 标题:ProtoMon: Embedded Monitors for Cryptographic Protocol Intrusion Detection and Prevention
  • 本地全文:下载
  • 作者:S. P. Joglekar, S. R. Tate
  • 期刊名称:Journal of Universal Computer Science
  • 印刷版ISSN:0948-6968
  • 出版年度:2005
  • 卷号:11
  • 期号:1
  • 页码:83-83
  • 出版社:Graz University of Technology and Know-Center
  • 摘要:Intrusion Detection Systems (IDS) are responsible for monitoring and analyzing host or network activity to detect intrusions in order to protect information from unauthorized access or manipulation. There are two main approaches for intrusion detection: signature-based and anomaly-based. Signature_based detection employs pattern matching to match attack signatures with observed data making it ideal for detecting known attacks. However, it cannot detect unknown attacks for which there is no signature available. Anomaly-based detection uses machine-learning techniques to create a profile of normal system behavior and uses this profile to detect deviations from the normal behavior. Although this technique is effective in detecting unknown attacks, it has a drawback of a high false alarm rate. In this paper, we describe our anomaly_based IDS designed for detecting malicious use of cryptographic and application-level protocols. Our system has several unique characteristics and benefits, such as the ability to monitor cryptographic protocols and application-level protocols embedded in encrypted sessions, a very lightweight monitoring process, and the ability to react to protocol misuse by modifying protocol response directly.
  • 关键词:Computer Security, Cryptographic Protocol Abuse, Intrusion Detection
国家哲学社会科学文献中心版权所有