메뉴 건너뛰기




Volumn 5, Issue 4, 2010, Pages 207-219

Enhancing intrusion detection system with proximity information

Author keywords

IDSes; Intrusion detection system; Security; Worm

Indexed keywords

ANOMALY DETECTION; COMPUTER CRIME;

EID: 78650662129     PISSN: 17478405     EISSN: 17478413     Source Type: Journal    
DOI: 10.1504/IJSN.2010.037660     Document Type: Article
Times cited : (14)

References (39)
  • 2
    • 78650633478 scopus 로고    scopus 로고
    • Towards software-based signature detection for intrusion prevention on the network card
    • ACM, Seattle, WA, USA
    • Bos, H. and Huang, K. (2005) 'Towards software-based signature detection for intrusion prevention on the network card', Proceedings of RAID, ACM, Seattle, WA, USA.
    • (2005) Proceedings of RAID
    • Bos, H.1    Huang, K.2
  • 4
    • 34548324846 scopus 로고    scopus 로고
    • Measuring network-aware worm spreading ability
    • Anchorage, AK, USA
    • Chen, Z. and Ji, C. (2007) 'Measuring network-aware worm spreading ability', Proceedings of IEEE INFOCOM, Anchorage, AK, USA, pp.116-124.
    • (2007) Proceedings of IEEE INFOCOM , pp. 116-124
    • Chen, Z.1    Ji, C.2
  • 5
  • 7
    • 38149011298 scopus 로고    scopus 로고
    • Swaddler: An approach for the anomaly-based detection of state violations in web applications
    • 5-7 September, Queensland, Australia
    • Cova, M., Balzarotti, D., Felmetsger, V. and Vigna, G. (2007) 'Swaddler: an approach for the anomaly-based detection of state violations in web applications', Proceedings of RAID, 5-7 September, Queensland, Australia, pp.63-86.
    • (2007) Proceedings of RAID , pp. 63-86
    • Cova, M.1    Balzarotti, D.2    Felmetsger, V.3    Vigna, G.4
  • 9
    • 0023294428 scopus 로고
    • An intrusion-detection model'
    • Denning, D.E. (1987) 'An intrusion-detection model', IEEE Trans. Softw. Eng., Vol. 13, No. 2, pp.222-232.
    • (1987) IEEE Trans. Softw. Eng. , vol.13 , Issue.2 , pp. 222-232
    • Denning, D.E.1
  • 10
    • 85077692116 scopus 로고    scopus 로고
    • Dynamic application-layer protocol analysis for network intrusion detection
    • USENIX Association, Berkeley, CA, USA
    • Dreger, H., Feldmann, A., Mai, M., Paxson, V. and Sommer, R. (2006) 'Dynamic application-layer protocol analysis for network intrusion detection', Proceeding of USENIX-SS'06, USENIX Association, Berkeley, CA, USA.
    • (2006) Proceeding of USENIX-SS'06
    • Dreger, H.1    Feldmann, A.2    Mai, M.3    Paxson, V.4    Sommer, R.5
  • 13
    • 33750309124 scopus 로고    scopus 로고
    • Enhancing network intrusion detection with integrated sampling and filtering
    • González, J.M. and Paxson, V. (2006) 'Enhancing network intrusion detection with integrated sampling and filtering', Proceedings of RAID, pp.272-289.
    • (2006) Proceedings of RAID , pp. 272-289
    • González, J.M.1    Paxson, V.2
  • 16
    • 35248819234 scopus 로고    scopus 로고
    • Using decision trees to improve signature-based intrusion detection
    • Krügel, C. and Toth, T. (2003) 'Using decision trees to improve signature-based intrusion detection', Proceedings of RAID, pp.173-191.
    • (2003) Proceedings of RAID , pp. 173-191
    • Krügel, C.1    Toth, T.2
  • 17
    • 77949731575 scopus 로고    scopus 로고
    • Temporal sequence learning and data reduction for anomaly detection'
    • Lane, T. and Brodley, C.E. (1999) 'Temporal sequence learning and data reduction for anomaly detection', ACM Trans. Inf. Syst. Secur., Vol. 2, No. 3, pp.295-331.
    • (1999) ACM Trans. Inf. Syst. Secur. , vol.2 , Issue.3 , pp. 295-331
    • Lane, T.1    Brodley, C.E.2
  • 18
    • 0032630098 scopus 로고    scopus 로고
    • Detecting computer and network misuse through the production-based expert system toolset (p-BEST)
    • Lindqvist, U. and Porras, P.A. (1999) 'Detecting computer and network misuse through the production-based expert system toolset (p-BEST)', IEEE Symposium on Security and Privacy, pp.146-161.
    • (1999) IEEE Symposium on Security and Privacy , pp. 146-161
    • Lindqvist, U.1    Porras, P.A.2
  • 19
    • 33745653877 scopus 로고    scopus 로고
    • Interactive visualization for network and port scan detection
    • Muelder, C., Ma, K-L. and Bartoletti, T. (2005) 'Interactive visualization for network and port scan detection', Proceedings of RAID, pp.265-283.
    • (2005) Proceedings of RAID , pp. 265-283
    • Muelder, C.1    Ma, K.-L.2    Bartoletti, T.3
  • 20
    • 38149083999 scopus 로고    scopus 로고
    • Exploiting execution context for the detection of anomalous system calls
    • Mutz, D., Robertson, W.K., Vigna, G. and Kemmerer, R.A. (2007) 'Exploiting execution context for the detection of anomalous system calls', Proceedings of RAID, pp.1-20.
    • (2007) Proceedings of RAID , pp. 1-20
    • Mutz, D.1    Robertson, W.K.2    Vigna, G.3    Kemmerer, R.A.4
  • 21
    • 0034782006 scopus 로고    scopus 로고
    • An investigation of geographic mapping techniques for internet hosts
    • DOI 10.1145/964723.383073
    • Padmanabhan, V.N. and Subramanian, L. (2001) 'An investigation of geographic mapping techniques for internet hosts', SIGCOMM '01, ACM, New York, NY, USA, pp.173-185. (Pubitemid 32981963)
    • (2001) Computer Communication Review , vol.31 , Issue.4 , pp. 173-185
    • Padmanabhan, V.N.1    Subramanian, L.2
  • 22
    • 38149093160 scopus 로고    scopus 로고
    • Emulation-based detection of non-self-contained polymorphic shellcode
    • Springer
    • Polychronakis, M., Anagnostakis, K.G. and Markatos, E.P. (2007) 'Emulation-based detection of non-self-contained polymorphic shellcode', Proceedings of RAID, Springer, Vol. 4637, pp.87-106.
    • (2007) Proceedings of RAID , vol.4637 , pp. 87-106
    • Polychronakis, M.1    Anagnostakis, K.G.2    Markatos, E.P.3
  • 25
    • 38149092413 scopus 로고    scopus 로고
    • Understanding precision in host based intrusion detection
    • Sharif, M.I., Singh, K., Giffin, J.T. and Lee, W. (2007) 'Understanding precision in host based intrusion detection', Proceedings of RAID, pp.21-41.
    • (2007) Proceedings of RAID , pp. 21-41
    • Sharif, M.I.1    Singh, K.2    Giffin, J.T.3    Lee, W.4
  • 30
    • 33750597720 scopus 로고    scopus 로고
    • Improving host-based ids with argument abstraction to prevent mimicry attacks
    • Sufatrio and Yap, R.H.C. (2005) 'Improving host-based ids with argument abstraction to prevent mimicry attacks', Proceedings of RAID, pp.146-164.
    • (2005) Proceedings of RAID , pp. 146-164
    • Sufatrio1    Yap, R.H.C.2
  • 31
    • 38149024764 scopus 로고    scopus 로고
    • The nids cluster: Scalable, stateful network intrusion detection on commodity hardware
    • Vallentin, M., Sommer, R., Lee, J., Leres, C., Paxson, V. and Tierney, B. (2007) 'The nids cluster: Scalable, stateful network intrusion detection on commodity hardware', Proceedings of RAID, pp.107-126.
    • (2007) Proceedings of RAID , pp. 107-126
    • Vallentin, M.1    Sommer, R.2    Lee, J.3    Leres, C.4    Paxson, V.5    Tierney, B.6
  • 34
    • 33750335757 scopus 로고    scopus 로고
    • Anagram: A content anomaly detector resistant to mimicry attack
    • Hamburg, Germany
    • Wang, K., Parekh, J.J. and Stolfo, S.J. (2006) 'Anagram: a content anomaly detector resistant to mimicry attack', Proceedings of RAID, Hamburg, Germany, pp.226-248.
    • (2006) Proceedings of RAID , pp. 226-248
    • Wang, K.1    Parekh, J.J.2    Stolfo, S.J.3
  • 35
    • 33646150900 scopus 로고    scopus 로고
    • On the performance of internet worm scanning strategies
    • Zou, C.C., Towsley, D. and Gong, W. (2006) 'On the performance of internet worm scanning strategies', Perform. Eval., Vol. 63, No. 7, pp.700-723.
    • (2006) Perform. Eval. , vol.63 , Issue.7 , pp. 700-723
    • Zou, C.C.1    Towsley, D.2    Gong, W.3
  • 36
    • 84946740842 scopus 로고    scopus 로고
    • Hostip, IP Address lookup, http://www.hostip.info/dl/ index.html
    • IP Address Lookup
  • 37
    • 78650655031 scopus 로고    scopus 로고
    • IP2Location, Geolocation IP address to Country City Region
    • IP2Location, Geolocation IP address to Country City Region
  • 38
    • 78650671654 scopus 로고    scopus 로고
    • Latitude Longitude
    • Latitude Longitude, http://www.ip2location.com/
  • 39
    • 84949506498 scopus 로고    scopus 로고
    • Libpcap, The Libpcap Project, http://sourceforge.net/projects/ libpcap/
    • The Libpcap Project


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.