Intrusion detection via static analysis
Wagner, D.; Dean, R.
Security and Privacy, 2001. S&P 2001. Proceedings. 2001 IEEE Symposium on
Volume , Issue , 2001 Page(s):156 - 168
Digital Object Identifier 10.1109/SECPRI.2001.924296
Summary:One of the primary challenges in intrusion detection is modelling
typical application behavior so that we can recognize attacks by their
atypical effects without raising too many false alarms. We show how
static analysis may be used to automatically derive a model of
application behavior. The result is a host-based intrusion detection
system with three advantages: a high degree of automation, protection
against a broad class of attacks based on corrupted code, and the
elimination of false alarms. We report on our experience with a
prototype implementation of this technique
View citation and abstract |