Title :
IDES: a progress report [Intrusion-Detection Expert System]
Author :
Lunt, Teresa F. ; Tamaru, Ann ; Gilham, Fred ; Jagannathan, R. ; Neumann, Peter G. ; Jalali, Caveh
Author_Institution :
Comput. Sci. Lab., SRI Int., Menlo Park, CA, USA
Abstract :
Describes a real-time intrusion-detection expert system (IDES), that observes user behavior on a monitored computer system and adaptively learns what is normal for individual users, groups, remote hosts, and the overall system behavior. Observed behavior is flagged as a potential intrusion if it deviates significantly from the expected behavior or if it triggers a rule in the expert-system rule base
Keywords :
adaptive systems; expert systems; learning systems; real-time systems; security of data; IDES; adaptive systems; learning systems; monitored computer system; real-time intrusion-detection expert system; Computer science; Computer security; Computerized monitoring; Data security; Expert systems; Laboratories; Protection; Prototypes; Real time systems; Remote monitoring;
Conference_Titel :
Computer Security Applications Conference, 1990., Proceedings of the Sixth Annual
Conference_Location :
Tucson, AZ
Print_ISBN :
0-8186-2105-2
DOI :
10.1109/CSAC.1990.143786