CAREER: Adaptive Intrusion Detection Systems
CAREER: Adaptive Intrusion Detection Systems
批准号:
0133629
负责人:
Wenke Lee
金额:
$35.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-08-15 至 2008-07-31
中文摘要
入侵检测是网络纵深防御安全机制的重要组成部分。当前的入侵检测系统(ids)对新的和复杂的攻击是无效的。本研究项目的主要目标是开发自适应入侵防御系统的算法、工具和系统架构。非自适应IDS需要检测新的攻击,并根据异常操作的变化进行调整。为此,研究了一种基于信息理论的异常检测框架。该方法首先利用信息论度量计算正常数据的规律性,然后根据规律性度量选择特征并构建检测模型。自适应IDS还需要自我监视其运行时工作负载和性能,并动态地重新配置其组件,以便在有限资源的情况下提供最佳检测功能。为此,研究了性能监控、负载减少、攻击场景分析和成本效益分析技术。通过本研究的出版物、算法和工具,研究人员和从业者可以了解自适应入侵防御系统的好处和技术。本研究对可生存网络系统、智能审计等相关领域也有重要贡献。最终,社会将受益于更有效、更健全的安全机制。
英文摘要
Intrusion detection is a critical component of the defense-in-depthnetwork security mechanisms. Current intrusion detection systems(IDSs) are ineffective against new and sophisticated attacks.The key objective of this research project is to develop thealgorithms, tools, and system architecture for adaptive IDSs. Anadaptive IDS needs to detect new attacks and adjust to changes innormal operations. Towards this end, an information-theoretic basedanomaly detection framework is investigated. The approach is to firstcompute the regularity of normal data using information-theoreticmeasures, then select features and construct a detection modelaccording to the regularity measures. An adaptive IDS needs to alsoself-monitor its run-time workload and performance, and dynamicallyreconfigure its components to provide the best detection capabilitygiven the limited resources. Towards this end, performance monitoring,load-shedding, attack scenario analysis, and cost-benefit analysistechniques are investigated.Through the publications and algorithms and tools from this research,researchers and practitioners can learn the benefits and techniques ofadaptive IDSs. This research also makes important contributions torelated fields, e.g., survivable network systems and smartauditing. Ultimately, the society will benefit from the more effectiveand robust security mechanisms.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
2015 Cyber Security Education Workshop
-
批准号:1544099
-
项目类别:Standard Grant
-
资助金额:$3.5万
-
财政年份:2015
-
负责人:Wenke Lee
-
依托单位:
TWC: Medium: Collaborative: Automated Reverse Engineering of Commodity Software
-
批准号:1409807
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2014
-
负责人:Wenke Lee
-
依托单位:
TWC SBE: TTP Option: Medium: Collaborative: EPICA: Empowering People to Overcome Information Controls and Attacks
-
批准号:1409635
-
项目类别:Standard Grant
-
资助金额:$110.0万
-
财政年份:2014
-
负责人:Wenke Lee
-
依托单位:
EAGER: The Conceptual Landscape of Information Manipulation
-
批准号:1255453
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2012
-
负责人:Wenke Lee
-
依托单位:
SaTC Cyber Cafe
-
批准号:1304678
-
项目类别:Standard Grant
-
资助金额:$5.34万
-
财政年份:2012
-
负责人:Wenke Lee
-
依托单位:
TC: Small: A Foundational and Practical Platform for Host Security Applications
-
批准号:1017265
-
项目类别:Standard Grant
-
资助金额:$42.96万
-
财政年份:2010
-
负责人:Wenke Lee
-
依托单位:
Collaborative Research: CT-L: CLEANSE: Cross-Layer Large-Scale Efficient Analysis of Network Activities to Secure the Internet
-
批准号:0831300
-
项目类别:Continuing Grant
-
资助金额:$66.89万
-
财政年份:2008
-
负责人:Wenke Lee
-
依托单位:
Collaborative Research: CT-T: Logic and Data Flow Extraction for Live and Informed Malware Execution
-
批准号:0716570
-
项目类别:Continuing Grant
-
资助金额:$22.0万
-
财政年份:2007
-
负责人:Wenke Lee
-
依托单位:
Collaborative Research: CT-ISG: Modeling and Measuring Botnets
-
批准号:0627477
-
项目类别:Continuing Grant
-
资助金额:$17.5万
-
财政年份:2006
-
负责人:Wenke Lee
-
依托单位:
Intrusion Detection Techniques for Mobile Ad Hoc Networks
-
批准号:0311024
-
项目类别:Continuing Grant
-
资助金额:$27.5万
-
财政年份:2003
-
负责人:Wenke Lee
-
依托单位:
海外基金