首页> 外文会议>Software Security and Reliability (SERE), 2012 IEEE Sixth International Conference on >Countering Network-Centric Insider Threats through Self-Protective Autonomic Rule Generation
【24h】

Countering Network-Centric Insider Threats through Self-Protective Autonomic Rule Generation

机译:通过自我保护的自主规则生成来应对以网络为中心的内部威胁

获取原文
获取原文并翻译 | 示例

摘要

Insider threats are a growing problem in today's organizations. Detecting such attacks is especially challenging because most system owners and system administrators use networks to remotely manage the systems they are responsible for. In previous work, we introduced the Autonomic Violation Prevention System (AVPS) that has a scalable architecture to deal with such threats. This system uses low level human-specified and manually-entered rules to protect networked applications from disgruntled privileged users. However, rule-based systems are generally difficult to maintain when the number of rules is too large. This paper addresses this problem by allowing human beings to enter a smaller number of high-level rules that are automatically translated into one or more low-level rules based on an analysis of the incoming network traffic. The paper discusses how various high level rules (HLR) can detect new unwanted behaviors without any user intervention. Experiments conducted on three types of applications -- FTP, database, and Web -- show that the enhanced AVPS can detect known and unknown insider attacks through high level rules and process automation.
机译:内部威胁是当今组织中日益严重的问题。由于大多数系统所有者和系统管理员都使用网络来远程管理其负责的系统,因此检测此类攻击尤其具有挑战性。在以前的工作中,我们介绍了具有防止此类威胁的可伸缩体系结构的自主防侵犯系统(AVPS)。此系统使用低级人员指定和手动输入的规则来保护联网应用程序免受不满的特权用户的侵害。但是,当规则数量太大时,通常很难维护基于规则的系统。本文通过允许人们输入少量高级规则来解决此问题,这些高级规则会根据对传入网络流量的分析自动转换为一个或多个低级规则。本文讨论了各种高级规则(HLR)如何在没有任何用户干预的情况下检测到新的有害行为。在FTP,数据库和Web三种类型的应用程序上进行的实验表明,增强的AVPS可以通过高级规则和流程自动化来检测已知和未知的内部攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号