Missouri University of Science and Technology
Lattice matching for detecting distributed intrusions
Abstract
dc:description.abstract"Intrusion detection systems (IDS) are crucial components of the security mechanisms of today's computer systems. Intrusion detection has been an active field of research for about three decades. Existing research on intrusion detection has focused on sequential intrusions. However, intrusions can also be formed by concurrent interactions of multiple processes. Some of the intrusions caused by these events cannot be detected using sequential intrusion detection methods. Therefore, there is a need for a mechanism that views the concurrent system as a whole. L-BID (Lattice-based intrusion detection) is proposed to address this problem. In the L-BID framework, a library of intrusions and collected distributed system traces are represented as lattices. Then these lattices are compared in order to infer to the existence of intrusion in the collected distributed system traces. The similarity between these lattices is used as a quantitative metric for L-BID. The applicability of lattice matching method to the concurrent intrusion detection problem is investigated and the challenging aspects of this work are outlined"--Abstract, page iii.
Degree
thesis:*- Name thesis:degree_name
- Ph. D. in Computer Science
- Grantor
- Missouri University of Science and Technology
- Year dc:date.available
- 2016
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Simsek, Sule
Subjects
dc:subject × 1Identifiers
dc:identifier.*- Repository record dc:identifier
- https://scholarsmine.mst.edu/doctoral_dissertations/1762
- OAI identifier oai:identifier
- oai:scholarsmine.mst.edu:doctoral_dissertations-2764