首页> 美国政府科技报告 >Storage-based Intrusion Detection: Watching storage activity for suspicious behavior
【24h】

Storage-based Intrusion Detection: Watching storage activity for suspicious behavior

机译:基于存储的入侵检测:监视存储活动是否存在可疑行为

获取原文

摘要

Storage-based intrusion detection allows storage systems to transparently watch for suspicious activity. Storage systems are well- positioned to spot several common intruder actions, such as adding backdoors, inserting Trojan horses, and tampering with audit logs. Further, an intrusion detection system (IDS) embedded in a storage device continues to operate even after client systems are compromised. This paper describes a number of specific warning signs visible at the storage interface. It describes and evaluates a storage IDS, embedded in an NFS server, demonstrating both feasibility and efficiency of storage-based intrusion detection. In particular, both the performance overhead and memory required (40 KB for a reasonable set of rules) are minimal. With small extensions, storage IDSs can also be embedded in block- based storage devices.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号