Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
My Menu
Saved Items

Misuse Detection

Improving the Efficiency of Misuse Detection

Michael MeierContact Information, Sebastian SchmerlContact Information and Hartmut KoenigContact Information

(1)  Brandenburg University of Technology Cottbus, Computer Science Department, P.O. Box 10 13 44, 03013 Cottbus, Germany
Abstract
In addition to preventive mechanisms intrusion detection systems (IDS) are an important instrument to protect computer systems. Most IDSs used today realize the misuse detection approach. These systems analyze monitored events for occurrences of defined patterns (signatures), which indicate security violations. Up to now only little attention has been paid to the analysis efficiency of these systems. In particular for systems that are able to detect complex, multi-step attacks not much work towards performance optimizations has been done. This paper discusses analysis techniques of IDSs used today and introduces a couple of optimizing strategies, which exploit structural properties of signatures to increase the analyze efficiency. A prototypical implementation has been used to evaluate these strategies experimentally and to compare them with currently deployed misuse detection techniques. Measurements showed that significant performance improvements can be gained by using the proposed optimizing strategies. The effects of each optimization strategy on the analysis efficiency are discussed in detail.

Contact Information Michael Meier
Email: mm@informatik.tu-cottbus.de

Contact Information Sebastian Schmerl
Email: sbs@informatik.tu-cottbus.de

Contact Information Hartmut Koenig
Email: koenig@informatik.tu-cottbus.de
Fulltext Preview (Small, Large)
Image of the first page of the fulltext


Export this chapter
Export this chapter as RIS | Text
 
Remote Address: 38.107.191.110 • Server: mpweb21
HTTP User Agent: CCBot/1.0 (+http://www.commoncrawl.org/bot.html)