Autor(en): Alderman, Ian D.
Parter, David W.
Rubin, Shai
Vernon, Mary K.
Titel: Foundations for Intrusion Prevention
Sprache (ISO): en
Zusammenfassung: We propose an infrastructure that helps a system administrator to identify a newly published vulnerability on the site hosts and to evaluate the vulnerability’s threat with respect to the administrator’s security priorities. The infrastructure foundation is the vulnerability semantics, a small set of attributes for vulnerability definition. We demonstrate that with a few attributes it is possible to define the majority of the known vulnerabilities in a way that (i) facilitates their accurate identification, and (ii) enables the administrator to rank the vulnerabilities found according to the organization’s security priorities. A large scale experiment demonstrates that our infrastructure can find significant vulnerabilities even in a site with a high security awareness.
Schlagwörter: Intrusion Prevention
URI: http://hdl.handle.net/2003/22840
http://dx.doi.org/10.17877/DE290R-14462
Erscheinungsdatum: 2004-07
Provinienz: Gesellschaft für Informatik
Zitierform: Rubin, Shai; Alderman, Ian D.; Parter, David W.; Vernon, Mary K.: Foundations for Intrusion Prevention. In Flegel, U.; Meier, M. (Eds.): Proc. of the International GI Workshop on Detection of Intrusions and Malware & Vulnerability Assessment, number P-46 in Lecture Notes in Informatics, pp. 143-160, Dortmund, Germany, July 2004, Köllen Verlag; ISBN 3-88579-365-X.
Ist Teil von: DIMVA 2004, July 6-7, Dortmund, Germany
Enthalten in den Sammlungen:Papers

Dateien zu dieser Ressource:
Datei Beschreibung GrößeFormat 
DIMVA2004-Rubin_et_al.pdf464.47 kBAdobe PDFÖffnen/Anzeigen


Diese Ressource ist urheberrechtlich geschützt.



Diese Ressource ist urheberrechtlich geschützt. rightsstatements.org