University of North Texas
Embedded monitors for detecting and preventing intrusions in cryptographic and application protocols.
Abstract
dc:descriptionThere are two main approaches for intrusion detection: signature-based and anomaly-based. Signature-based detection employs pattern matching to match attack signatures with observed data making it ideal for detecting known attacks. However, it cannot detect unknown attacks for which there is no signature available. Anomaly-based detection builds a profile of normal system behavior to detect known and unknown attacks as behavioral deviations. However, it has a drawback of a high false alarm rate. In this thesis, we describe our anomaly-based IDS designed for detecting intrusions in cryptographic and application-level protocols. Our system has several unique characteristics, such as the ability to monitor cryptographic protocols and application-level protocols embedded in encrypted sessions, a very lightweight monitoring process, and the ability to react to protocol misuse by modifying protocol response directly.
Degree
thesis:*- Grantor dc:publisher
- University of North Texas
- Year dc:date
- 2003
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Joglekar, Sachin P.
- Contributors dc:contributor
-
- Tate, Stephen R.
- Mikler, Armin R.
- Dantu, Ram
Subjects
dc:subject × 7Rights
dc:rights- Statement dc:rights
-
- Public
- Copyright
- Joglekar, Sachin P.
- Copyright is held by the author, unless otherwise noted. All rights reserved.
- Language dc:language
- English
Identifiers
dc:identifier.*- Identifier
-
oclc: 54446883
https://digital.library.unt.edu/ark:/67531/metadc4414/
ark: ark:/67531/metadc4414 - OAI identifier oai:identifier
- info:ark/67531/metadc4414