The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Reports and Papers Archive


Browse All Papers »       Submit A Paper »

Intrusion Detection Systems and a View to Its Forensic Applications

Traditional computer security has often emphasized prevention, and to a lesser degree, the detection of system security violations.  However, it is recognized that the forensic aspect to the overall model of computer security is equally as important.  The area of computer forensics lends itself heavily to the response of a criminal violation that has already occurred ono a system.  This paper views a forensic application within the framework of Intrusion Detection and details work accomplished on a prototype anomaly Intrusion Detection system.

Added 2002-07-26

Mining in a Data-flow Environment: Experience in a Network Intrusion Detection

Wenke Lee, Salvatore J. Stolfo, Kui W. Mok

We discuss the KDD process in \“data-flow\” environments, where unstructured and time dependent data can be processed into various levels of structured and semantically-rich forms for analysis tasks.  Using network intrusion detection as a concrete application example, we describe how to construct models that are both accurate in describing the underlying concepts, and efficient when used to analyze data in real-time.  We prsent procedures for analyzing frequent patterns from lower level data and constructing appropriate features to formuate higher level data.  The features generated from various levels of data have different computational costs (in time and space).  We show that in order to minimize the time required in using the classification models in real-time environment, we can exploit the \“necessary conditions\” associated with the low-cost features to determine whether some high-cost features need to be computed and the corresponding classification rules need to be checked.  We have applied our tools to the problem of building network intrusion detection models.  We report our experiments using the network data provided as part of the 1998 DARPA Intrusion detection Evaluation program.  We also discuss our experience in using the mined models in NFR, a real-time network intrusion detection system.

Added 2002-07-26

Experience with Emerald to Date

Peter G. Neumann and Phillip A. Porras

After summarizing the EMERALD architecture and the evolutionary process from which EMERALD has evolved, this paper focuses on our experienceto date in designing, implementing, and applying EMERALD to various types of anomalies and misuse.  The discussion addresses the fundamental importance of good software engineering practice and the importance of the system architecture….

Added 2002-07-26

Synthesizing Fast Intrusion Prevention/detection Systems from High-Level Specifications

R. Sekar, P. Uppuluri

To build survivable information systems (i.e., systems that continue to provide their services in spite of coordinated attacks), it is necessary to detect and isolate intrusions before they impact system performance or functionality.  Previous research in this area has focused primarily on detecting intrusions after the fact, rather than preventing them in the first place.  We have developed a new approach based on specifying intended program behaviors using patterns over sequences of system calls.  The pattern can also capture conditions on the values of system-call arguments.  At runtime, we intercept the system calls made by processes, compare them against specifications, and disallow (or otherwise modify) those calls that deviate from specifications.  Since our approach is capable of modifying a system call before it is delivered to the operating system kernel, it is capable of reacting before any damage-causing system call is executed by a process under attack.  We present our specification language and illustrate its use by developing a specification for the ftp server.  Observe that in our approach, every system call is intercepted and subject to potentially expensive operations for matching against many patterns that specify normal/abnormal behavior.  Thus , minimizing the overheads incurred for pattern-matching is critical for the viability of our approach.  We solve this problem by developing a new, low-overhead algorithm for matching runtime behaviors against specifications.  A salient feature of our algorithm is that its runtime is almost independent of the number of patterns.  In most cases, it uses a constant amount of time per system call intercepted, and uses a constant amount of storage, both independent of either the size or number of patterns.  These benefits make our algorithm useful for many other intrusion detection methods that employ pattern-matching.  We describe our algorithm, and evaluate its performance through experiments.

Added 2002-07-26


Moblie Agent Security

Christian F. Tschudin
Added 2002-07-26

With Microscope and Tweezers: The Worm from MIT's Perspective

Jon A. Rochlis and Mark W. Eichin
Added 2002-07-26

Generalized Temporal Role Based Access Control Model (GTRBAC) (Part I) - Specification and Modeling

CERIAS TR 2001-47
James B. D. Joshi, Elisa Bertino, Usman Latif, Arif Ghafoor
Download: PDF

A temporal RBAC (TRBAC) model has recently been proposed that addresses the temporal aspects of roles and trigger-based role enabling. However, it is limited to constraints on enabling of roles only. We propose a Generalized Temporal Role Based Access Control model (GTRBAC) that is capable of expressing a wider range of temporal constraints. GTRBAC is capable of expressing periodic as well as duration constraints on roles, user-role assignments and role-permission assignments. In GTRBAC, temporal constraints on role enablings and role activations can be separately specified. A user-activated role can further be restricted to various activation constraints such as cardinality constraint or maximum active duration constraint within a specified interval. The GTRBAC model extends the syntactic structure of TRBAC model and its event and trigger expressions subsume those of TRBAC.

Added 2002-07-26

Reasoning about Belief in Cryptographic Protocols

Li Gong, Roger Needham, and Raphael Yahalom

Analysis methods for cryptographic protocols have often focused on information leakage rather than on seeing whether a protocol meets its goals.  Many protocols, however, fall far short of meeting their goals, sometimes for quite subtle reasons

Added 2002-07-26


Temporal Hierarchy and Inheritance Semantics for GTRBAC

CERIAS TR 2001-52
James B. D. Joshi, Elisa Bertino, Arif Ghafoor
Download: PDF

A Generalized Temporal Role Based Access Control (GTRBAC) model that captures an exhaustive set of temporal constraint needs for access control has recently been proposed. GTRBAC

Added 2002-07-26

Privacy-Preserving Cooperative Scientific Computations

CERIAS TR 2001-50
Wenliang Du and Mikhail J. Atallah
Download: PDF
Added 2002-07-26

Optimizing TCP Forwarder Performance

Oliver Spatscheck, Jorgen S. Hansen, John H. Hartman, and Larry L. Peterson

A TCP forwarder is a network node that establishes and forwards data between a pair of TCP connections.  For example, a firewall that places a proxy between a TCP connection to an external host and a TCP connection to an internal host - for the purpose of implementing access control to a resource on the internal host - is an example of a TCP forwarder.

Added 2002-07-26

Cooperating Moblie Agents for Mapping Networks

Nelson Minar, Kwindla Hultman Kramer, and Pattie Maes

Contemporary computer networks are heterogeneous; even a single network consists of many kinds of processors and communications channels.  But few programming tools embrace, or even acknowledge, this complexity.  New methods and approaches are required if next-generation networks are to be configured, administered and utilized to their full potentials…

Added 2002-07-26

A Middleware Approach to Asynchronous and Backward-Compatible Detection and Prevention of ARP Cache Poisoning

CERIAS TR 1999-07
Mahesh V. Tripunitara and Partha Dutta
Download: PDF

This paper discusses the Address Resolution Protocol (ARP) and the problem of cache poisoning.  ARP cache poisoning is the malicious act, by a host in a LAN, of introducing a spurious IP address to MAC (Ethernet) address mapping in another host\‘s ARP cache…

Added 2002-07-26