D. S. Bauer, F.R. Eichelman, R.M. Herrera, A.E. Irgon
{"title":"Intrusion detection: an application of expert systems to computer security","authors":"D. S. Bauer, F.R. Eichelman, R.M. Herrera, A.E. Irgon","doi":"10.1109/CCST.1989.751961","DOIUrl":null,"url":null,"abstract":"Audit trails have long been an important component of a comprehensive computer security program. Unfortunately, the collected audit data is often not regularly analyzed and, in many cases, never even reviewed unless computer abuse is suspected. Many computer intrusions could very likely be discovered quickly if computer system audit trails were inspected on a regular basis by experts trained to recognize intrusive behavior. Intrusion Detection is a new research area in computer security focusing on developing the technology to detect intruders on computer systems in near real-time through the use of software systems that automatically analyze computer system audit trails. This paper presents an overview of current intrusion detection research and technology, The Network Intrusion Detection Expert System (NIDX), a software system recently prototyped by Bellcore, is described as an example of an Intrusion Detection System (IDS).","PeriodicalId":288105,"journal":{"name":"Proceedings. International Carnahan Conference on Security Technology","volume":"2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1989-10-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings. International Carnahan Conference on Security Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CCST.1989.751961","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8
Abstract
Audit trails have long been an important component of a comprehensive computer security program. Unfortunately, the collected audit data is often not regularly analyzed and, in many cases, never even reviewed unless computer abuse is suspected. Many computer intrusions could very likely be discovered quickly if computer system audit trails were inspected on a regular basis by experts trained to recognize intrusive behavior. Intrusion Detection is a new research area in computer security focusing on developing the technology to detect intruders on computer systems in near real-time through the use of software systems that automatically analyze computer system audit trails. This paper presents an overview of current intrusion detection research and technology, The Network Intrusion Detection Expert System (NIDX), a software system recently prototyped by Bellcore, is described as an example of an Intrusion Detection System (IDS).