Whodunnit?: an intrusion analysis system

annual information security symposium(2004)

引用 23|浏览1
暂无评分
摘要
Intrusion analysis has traditionally been a very arduous and largely manual task. The reasons vary from insufficient logs to lack of proper tools for analysing the available audit logs. In our work, we hope to build an intrusion analysis system that could provide precise answers, efficiently, to the most commonly asked questions by the system administrators investigating an intrusion. We take the view that, the failings of today's intrusion analysis tools can be largely attributed to insufficient auditing. In our work, we capture all the necessary dependency relationships between the system events so that precise intrusion analysis is possible.
更多
查看译文
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要