首页> 外文会议>Annual Hawaii International Conference on System Sciences >On-Line Intrusion Detection and Attack Prevention Using Diversity, Generate-and-Test, and Generalization
【24h】

On-Line Intrusion Detection and Attack Prevention Using Diversity, Generate-and-Test, and Generalization

机译:使用多样性,生成和测试和泛化,在线入侵检测和攻击预防

获取原文
获取外文期刊封面目录资料

摘要

We have built a system for protecting Internet services to securely connected, known users. It implements a generate-and-test approach for on-line attack identification and uses similarity rules for generalization of attack signatures. We can immediately protect the system from many variants of previously unknown attacks without debilitating waits for anti-virus updates or software patches. Unique to our approach is the use of diverse process pairs not only for isolation benefits but also for detection. The architecture uses the comparison of outputs from diverse applications to provide a significant and novel intrusion detection capability. With this technique, we gain the benefits of n-version programming without its controversial disadvantages. The isolation of intrusions is mainly achieved with an out-of-band control system that separates the primary and backup system. It also initiates attack diagnosis and blocking, and recovery, which is accelerated by continual repair.
机译:我们建立了一种保护互联网服务以安全地连接的已知用户的系统。它实现了用于在线攻击识别的生成和测试方法,并使用相似性规则以呈现攻击签名的泛化。我们可以立即保护系统免受先前未知攻击的许多变体,而无需衰弱等待反病毒更新或软件补丁。我们的方法是独一无二的,不仅可以使用不同的过程对,不仅用于隔离益处,还用于检测。该架构使用各种应用的输出的比较来提供显着和新的入侵检测能力。通过这种技术,我们在没有争议的缺点的情况下获得了N-Version编程的好处。侵入的分离主要通过带外控制系统分离主和备用系统。它还启动攻击诊断和阻塞,恢复,通过持续修复加速。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号