GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • IMF - IT-Incident Management & IT-Forensics
  • P140 - IMF 2008 – IT-Incident Management & IT Forensics
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • IMF - IT-Incident Management & IT-Forensics
  • P140 - IMF 2008 – IT-Incident Management & IT Forensics
  • Dokumentanzeige

Using observations of invariant behaviour to detect malicious agency in distributes environments

Autor(en):
McEvoy, Thomas Richard [DBLP] ;
Wolthusen, Stephen [DBLP]
Zusammenfassung
Detecting malicious software used for covert ends is problematical because skilled attackers invariably employ stealth mechanisms to conceal the injection and subsequent activity of such software. As a result, the evidence of such incursions, frequently "disappears" once the attack has succeeded. In distributed environments, this difficulty is compounded because of the inherent difficulties in observing the global state of a computation. We propose a novel approach to the detection of potentially malicious activity in distributed environments. We select key data elements, which are chosen on the basis that they are frequently subject to subversion during malicious attacks. We specify their behavior as a partial order of sequences in state, accounting not only for legal and illegal states, but also for less than normative behavior, whose occurrence may indicate the presence of anomalous conditions. We show how we overcome the difficulties of observing state in distributed environments through employing a multiplicity of distinct and independent observer processes and by making use of well-known algorithms to synchronize and order our observations and we demonstrate that we are able to use the resulting data set to make inferences about the presence (or not) of malicious software based on comparisons of observed and expected behaviors.
  • Vollständige Referenz
  • BibTeX
McEvoy, T. R. & Wolthusen, S., (2008). Using observations of invariant behaviour to detect malicious agency in distributes environments. In: Göbel, O., Frings, S., Günther, D., Nedon, J. & Schadt, D. (Hrsg.), IMF 2008 – IT Incident Management & IT Forensics. Bonn: Gesellschaft für Informatik e.V.. (S. 55-72).
@inproceedings{mci/McEvoy2008,
author = {McEvoy, Thomas Richard AND Wolthusen, Stephen},
title = {Using observations of invariant behaviour to detect malicious agency in distributes environments},
booktitle = {IMF 2008 – IT Incident Management & IT Forensics},
year = {2008},
editor = {Göbel, Oliver AND Frings, Sandra AND Günther, Detlef AND Nedon, Jens AND Schadt, Dirk} ,
pages = { 55-72 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
DateienGroesseFormatAnzeige
gi-proc-140-006.pdf167.3Kb PDF Öffnen

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

ISBN: 978-3-88579-234-5
ISSN: 1617-5468
Datum: 2008
Sprache: en (en)
Typ: Text/Conference Paper
Sammlungen
  • P140 - IMF 2008 – IT-Incident Management & IT Forensics [15]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.