MetaCartSign in to MyCiteSeer

Include Citations | Advanced Search | Help

Include Citations | Advanced Search | Help

  Responses to Anomalous Live Disturbances) en-

Download:
Download as a PDF | Download as a PS
by Phillip A. Porras, Peter G. Neumann
http://www2.csl.sri.com/emerald/Emerald-NISS97.ps.gz
Add To MetaCart

Abstract:

vironment is a distributed scalable tool suite for track-ing malicious activity through and across large networks. EMERALD introduces a highly distributed, buildingblock approach to network surveillance, attack isolation, and automated response. It combines models from research in distributed high-volume event-correlation methodologies with over a decade of intrusion detection research and engineering experience. The approach is novel in its use of highly distributed, independently tunable, surveillance and response monitors that are deployable polymorphically at various abstract layers in a large network. These monitors contribute to a streamlined event-analysis system that combines signature analysis with statistical profiling to provide localized real-time protection of the most widely used network services on the Internet. Equally important, EMERALD introduces a recursive framework for coordinating the dissemination of analyses from the distributed monitors to provide a global detection and response capability that can counter attacks occurring across an entire network enterprise. Further, EMERALD introduces a versatile application programmers ' interface that enhances its ability to integrate with heterogeneous target hosts and provides a high degree of interoperability with third-party tool suites.

Citations

206 State Transition Analysis: A Rule-Based Intrusion Detection Approach – Ilgun, Kemmerer, et al. - 1995
122 Execution monitoring of security-critical programs in distributed systems: A specification-based approach – Ko, Ruschitzka, et al. - 1997
108 The NIDES Statistical Component: Description and Justification – Javitz, Valdes - 1994
72 GrIDS - A Graph Based Intrusion Detection System For Large Networks – Staniford-Chen, Cheung, et al. - 1996
56 A coding approach to event correlation – Kliger, Yemini, et al. - 1995
41 Computer-Related Risks – Neumann - 1995
38 Monitoring of Distributed Systems – Mansouri-Samani - 1995
33 Active Defense of Computer Systems Using Autonomous Agents – Crosbie, Spafford - 1995
31 Alarm Correlation – Jakobson, Weissman - 1993
28 With Microscope and Tweezers: The Worm from MIT’s Perspective – Rochlis, Eichin - 1989
20 Next-generation intrusion-detection expert system (nides – Anderson, Frivold, et al. - 1995
20 Decentralizing control and intelligence in network management – Meyer, Erlinger, et al. - 1995
14 Safeguard final report: detecting unusual program behavior using the NIDES statistical component – Anderson, Lunt, et al. - 1993
14 A method to detect intrusive activity in a networked environment – Heberlein, Mukherjee, et al. - 1991
7 Analytical techniques development for a statistical intrusion-detection system (SIDS) based on accounting records – Javitz, Valdes, et al. - 1986
7 Modeling Correlated Alarms in Network Management Systems – Ricciulli, Shacham - 1997
4 Requirements and model for IDES a real-time intrusion-detection expert system – Denning, Neumann - 1985
4 Vulnerabilities of network control protocols – Rosen - 1981
3 An architecture for a distributed intrusion detection system – Brentano, Snapp, et al. - 1991
2 Conceptual design and planning for EMERALD: event monitoring enabling responses to anomalous live disturbances – Porras, Neumann - 1997
2 The Internet Worm: crisis and aftermath – Spafiord - 1989
1 Computer security tec}mology planning study – Anderson - 1972
1 Industrialespionagetoday and information wars of tomorrow – Joyal - 1996