A context-based analysis of intrusion detection for policy violation

作者:Wan Kaiyu*; Alagar Vasu; Yang Zhong Yuan
来源:International Conference on Computational Intelligence and Security, 2007-12-15 to 2007-12-19.

摘要

Existing intrusion detection systems (IDS) operate independently from security policy enforcement mechanism. In current IDS the functionality has been restricted to detecting only anomaly in system behavior and system misuse. In order to assist system administrators in restoring and strengthening system security after an intrusion is detected this paper proposes a method that will link the security Violation to a non-empty, subset of the policy base. A multiagent system is proposed to automate the intrusion detection and analysis.