Publikationsserver der RWTH Aachen University
Angriffserkennung in Kommunikationsnetzen
Abstract
dc:descriptionConventional security mechanisms can be overcome by attackers. Therefore, additional systems, so-called intrusion detection systems, are used in communication networks in order to detect such attacks. These systems continuously monitor a network and analyse the recorded events. The analysis can either be done with regard to already known attack signatures (misuse detection), or with regard to deviations from the expected behaviour (anomaly detection). This thesis proposes a new method of anomaly detection. The so-called transaction-based anomaly detection uses a formal definition of the expected behaviour, and is based on the concept of transactions. Transactions originate from the field of databases. In this thesis the transaction properties of atomicity, consistency, isolation and durability (ACID properties) are applied to communication protocols. This enables the classification of possible attacks as well as the development of procedures for the detection of anomalies and the adaptive control of countermeasures.
Degree
thesis:*- Grantor dc:publisher
- Publikationsserver der RWTH Aachen University
- Year dc:date
- 2001
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Büschkes, Roland
- Contributors dc:contributor
-
- Spaniol, Otto
Subjects
dc:subject × 12Rights
dc:rights- Statement dc:rights
-
- info:eu-repo/semantics/openAccess
- Language dc:language
- ger
Identifiers
dc:identifier.*- OAI identifier oai:identifier
- oai:publications.rwth-aachen.de:58985