CSE497b Introduction to Computer and Network Security - Spring 2007 - Professor Jaeger
Intrusion Detection Systems
CSE497b - Spring 2007 Introduction Computer and Network Security Professor Jaeger
www.cse.psu.edu/~tjaeger/cse497b-s07/
Intrusion Detection Systems CSE497b - Spring 2007 Introduction - - PowerPoint PPT Presentation
Intrusion Detection Systems CSE497b - Spring 2007 Introduction Computer and Network Security Professor Jaeger www.cse.psu.edu/~tjaeger/cse497b-s07/ CSE497b Introduction to Computer and Network Security - Spring 2007 - Professor Jaeger
CSE497b Introduction to Computer and Network Security - Spring 2007 - Professor Jaeger
CSE497b - Spring 2007 Introduction Computer and Network Security Professor Jaeger
www.cse.psu.edu/~tjaeger/cse497b-s07/
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
that a system will not be secure, but that violations of security policy (intrusions) can be detected by monitoring and analyzing system behavior.” [Forrest 98]
2
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
3
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
(generally true?)
4
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
to distinguish from normal behavior
5
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
6
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
7
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
– n-grams of system call sequences (learned)
8
WRITE READ WRITE SEND SEND READ WRITE SEND Event Stream Attack Profile
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
– A system can exhibit all sorts of behavior
– context sensitive
9
Abnormal Normal Legal
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
infrastructure
10
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
11
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
12
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
13
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
14
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
15
!"#$%&' !"#&%$' !"#$' !"#&' ( !"#)**' !"#)+++,' !"#)+,++*-' ( ( )++*-
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
16
Attack Density P(T) Detector Flagging Pr(F) Detector Accuracy Pr(F|T) True Positives P(T|F)
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
17
Attack Density P(T) Detector Flagging Pr(F) Detector Accuracy Pr(F|T) True Positives P(T|F)
CSE497b Introduction to Computer (and Network) Security - Spring 2007 - Professor Jaeger
nothing to do with bad science
18