首页> 外文会议>Information Assurance Workshop, 2003. IEEE Systems, Man and Cybernetics Society >Automatic backdoor analysis with a network intrusion detection system and an integrated service checker
【24h】

Automatic backdoor analysis with a network intrusion detection system and an integrated service checker

机译:利用网络入侵检测系统和集成的服务检查器进行自动后门分析

获取原文

摘要

We examine how a network intrusion detection system can be used as a trigger for service checking and reporting. This approach reduces the amount of false alerts (false positives) and raises the quality of the alert report. A sample data over the Christmas period of year 2002 is analyzed as an example and detection of unauthorized SSH servers used as the main application. Unauthorized interactive backdoors to a network belong to the most dangerous class of intrusions (D. Zamboni et al., 1998). These backdoors are usually installed by root-kits, to hide the system compromise activity. They are a gateway to launch exploits, gain super-user access to hosts in the internal network and use the attacked network as a stepping stone to attack other networks. In this research, we have developed software and done statistical analysis to assess and prevent such situations.
机译:我们研究了如何将网络入侵检测系统用作服务检查和报告的触发器。这种方法减少了错误警报(误报)的数量,并提高了警报报告的质量。以2002年圣诞节期间的样本数据为例进行分析,并检测未经授权的SSH服务器作为主要应用程序。未经授权的网络交互式后门属于最危险的入侵类别(D. Zamboni等,1998)。这些后门通常由root-kit安装,以隐藏系统危害活动。它们是启动攻击的网关,可以让超级用户访问内部网络中的主机,并将被攻击的网络用作攻击其他网络的垫脚石。在这项研究中,我们开发了软件并进行了统计分析,以评估和预防此类情况。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号