DocumentCode
2586942
Title
One size does not fit all: 10 years of applying context-aware security
Author
Sinha, Sushant ; Bailey, Michael ; Jahanian, Farnam
Author_Institution
Comput. Sci. & Eng., Univ. of Michigan, Ann Arbor, MI, USA
fYear
2009
fDate
11-12 May 2009
Firstpage
14
Lastpage
21
Abstract
Defenders of today´s critical cyber-infrastructure (e.g., the Internet) are equipped with a wide array of security techniques including network-based intrusion detection systems (IDS), host-based anti-virus systems (AV), and decoy or reconnaissance systems such as host-based honeypots or network-based telescopes. While effective at detecting and mitigating some of the threats posed to critical infrastructure, the ubiquitous nature of malicious activity (e.g., phishing, spam, DDoS) on the Internet indicates that the current deployments of these tools do not fully live up to their promise. Over the past 10 years our research group has investigated ways of detecting and stopping cyber-attacks by using the context available in the network, host, and the environment. In this paper, we explain what exactly we mean by context, why it is difficult to measure, and what one can do with context when it is available. We illustrate these points by examining several studies in which context was used to enable or enhance new security techniques. We conclude with some ideas about the future of context-aware security.
Keywords
Internet; computer viruses; telecommunication security; ubiquitous computing; Internet; antivirus systems; context-aware security; critical cyber-infrastructure; network-based intrusion detection systems; reconnaissance systems; Computer science; Computer security; Context; IP networks; Information security; Internet; Intrusion detection; Operating systems; Reconnaissance; Telescopes;
fLanguage
English
Publisher
ieee
Conference_Titel
Technologies for Homeland Security, 2009. HST '09. IEEE Conference on
Conference_Location
Boston, MA
Print_ISBN
978-1-4244-4178-5
Type
conf
DOI
10.1109/THS.2009.5168009
Filename
5168009
Link To Document