• DocumentCode
    2300910
  • Title

    An Event-Driven Architecture for Fine Grained Intrusion Detection and Attack Aftermath Mitigation

  • Author

    Peng, Jianfeng ; Feng, Chuan ; Qiao, Haiyan ; Rozenblit, Jerzy

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Arizona Univ., Tucson, AZ
  • fYear
    2007
  • fDate
    26-29 March 2007
  • Firstpage
    55
  • Lastpage
    62
  • Abstract
    In today´s computing environment, unauthorized accesses and misuse of critical data can be catastrophic to personal users, businesses, emergency services, and even national defense and security. To protect computers from the ever-increasing threat of intrusion, we propose an event-driven architecture that provides fine grained intrusion detection and decision support capability. Within this architecture, an incoming event is scrutinized by the subject-verb-object multipoint monitors. Deviations from normal behavior detected by SVO monitors will trigger different alarms, which are sent to subsequent fusion and verification modules to reduce the false positive rate. The system then performs impact analysis by studying real-time system metrics, collected through the Windows management instrumentation interface. We add to the system the capability to assist the administrator in taking effective actions to mitigate the aftermath of an intrusion
  • Keywords
    formal verification; real-time systems; security of data; software architecture; software metrics; systems analysis; Windows management instrumentation interface; attack aftermath mitigation; decision support; event-driven architecture; impact analysis; intrusion detection; real-time system metrics; subject-verb-object multipoint monitoring; unauthorized accesses; verification modules; Computer architecture; Computer displays; Data security; Emergency services; Instruments; Intrusion detection; National security; Performance analysis; Protection; Real time systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Engineering of Computer-Based Systems, 2007. ECBS '07. 14th Annual IEEE International Conference and Workshops on the
  • Conference_Location
    Tucson, AZ
  • Print_ISBN
    0-7695-2772-8
  • Type

    conf

  • DOI
    10.1109/ECBS.2007.18
  • Filename
    4148919