newsletterlibrary.com

Top : Computers : Security : Intrusion Detection Systems :
Research

Websites
Perdue University's clearinghouse for intrusion detection information. Includes overviews, policy, detection methods, and tools.
http://www.cerias.purdue.edu/abo...t_resources/intrusion_detection/

The RAID workshop series is an annual event dedicated to the sharing of information related to the intrusion-detection area.
http://www.raid-symposium.org/

The Reliable Software Group (RSG) works on languages and tools for designing, building, and validating software systems. Specific areas that the group has targeted include concurrent and real-time systems. We are also investigating techniques for increasing the security of computer systems, with particular emphasis on analyzing encryption protocols using machine aided formal verification techniques, modeling and analyzing covert channels, modeling and detecting computer intrusions, analyzing mobile code and Web browsers for security violations, and approaches to secure Internet computing with unsecure applications.
http://www.cs.ucsb.edu/~rsg/STAT/

Information Assurance focusing on techniques for detecting and reacting to intrusions into networked information systems. We have coordinated several evaluations of computer network intrusion detection systems.
http://www.ll.mit.edu/IST/

This project is a data-mining based approach to detecting intruders in computer systems. The project approaches the intrusion detection problem from a data-mining perspective. Large quantities of data are collected from the system and analyzed to build models of normal behavior and intrusion behavior. These models are evaluated on data collected in real time to detect intruders.
http://www.cs.columbia.edu/ids/

The Cooperative Intrusion Detection Evaluation and Response project is an effort of NSWC Dahlgren, NFR, NSA, the SANS community and other interested parties to locate, document, and improve security software.
http://www.nswc.navy.mil/ISSEC/CID/

The purpose of the Intrusion Detection Working Group is to define data formats and exchange procedures for sharing information of interest to intrusion detection and response systems, and to management systems which may need to interact with them. The Intrusion Detection Working Group will coordinate its efforts with other IETF Working Groups.
http://www.ietf.org/html.charters/idwg-charter.html

Four examples of how we are applying ideas from immunology to today's computer security problems are a host based intrusion-detection method, a network based intrusion-detection system, a distributable change-detection algorithm, and a method for intentionally introducing diversity to reduce vulnerability.
http://www.cs.unm.edu/~immsec/

Hummer is a distributed component for any Intrusion Detection System ; Magpie is a hierarchical network of lightweight, mobile, and adaptive tools designed to both investigate and guard against intrusions.
http://www.csds.uidaho.edu/

A Data Mining Approach for Building Cost-sensitive and Light Intrusion Detection Models
http://www.cc.gatech.edu/~wenke/project/id.html

Anomaly Detection in Database Systems, Common Intrusion Detection Framework, Intrusion Detection and Isolation Protocol / IDIP, Intrusion Detection for Large Networks, Misuse Detection and Workshop for Intrusion Detection and Response Data Sharing.
http://seclab.cs.ucdavis.edu/

Aims to develop protocols and application programming interfaces so that intrusion detection research projects can share information and resources and so that intrusion detection components can be reused in other systems.
http://www.isi.edu/gost/cidf/

This homepage provides general information about IDSs as well as specific information about the project 'OtO'.
http://www.students.fh-sbg.ac.at/~messl/

The Intrusion Detection (ID) Research Group at NC State University was formed by Dr. Peng Ning in August 2002.
http://discovery.csc.ncsu.edu/index.html

Research project focused on the development of high performance data mining algorithms and tools that will provide support required to analyze the massive data sets generated by various processes that monitor computing and information systems.
http://www.cs.umn.edu/research/minds/

A mission-impact-based approach to INFOSEC alarm correlation.
http://www.sdl.sri.com/papers/mcorrelator/

Research institute actively involved in intrusion-detection research since 1983. Research focuses on EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances, a system designed to detect and respond to network attacks.
http://www.sdl.sri.com/programs/intrusion/

A group mailing focusing on security information management, intrusion response, intrusion detection, intrusion prevention, intrusion management and honeynets/honeypots.
http://idug.cryptojail.net

Research focuses on methods of improving the technical approach of identifying and preventing security flaws, limiting the damage from attacks, and ensuring that systems continue to provide essential services despite of compromises or failures.
http://www.cert.org/nav/index_purple.html

ResearchIndex is a scientific literature digital library that aims to improve the dissemination and feedback of scientific literature, and to provide improvements in functionality, usability, availability, cost, comprehensiveness, efficiency, and timeliness.
http://citeseer.ist.psu.edu/Security/IntrusionDetection/

Selected articles and papers related to intrusion detection research.
http://ids.homeunix.org/article.php

INBOUNDS is a network-based, real-time, hierarchical intrusion detection system being developed at Ohio University. INBOUNDS detects suspicious behavior by scrutinizing network information generated by Tcprace, and host data gathered by the monitors of DeSiDeRaTa. INBOUNDS functions in a heterogeneous environment with fault tolerance, very low overhead, and a high degree of scalability.
http://zen.ece.ohiou.edu/~inbounds/index.shtml

Research project that utilizes network attack variations to make more precise statements about the detection capabilities of an IDS.
http://thor.cryptojail.net

International Symposium on Recent Advances in Intrusion Detection. Held in conjunction with ESORICS 2004, September 15-17, 2004. The RAID International Symposium series is intended to advance the field of intrusion detection by promoting the exchange of ideas on a broad range of topics, bringing together leading experts from academia, government, and industry to discuss state-of-the-art intrusion detection technologies and issues from research and commercial perspectives.
http://raid04.eurecom.fr

Mobile Agent Intrusion Detection System (MAIDS) design and implementation research at Iowa State University.
http://latte.cs.iastate.edu/Research/Intrusion/index.html

SRI International's EMERALD (Event Monitoring Enabling Responses to Anomalous Live Disturbances) research project is a distributed scalable tool suite for tracking malicious activity through and across large networks.
http://www.sdl.sri.com/projects/emerald/

Security Incident Fusion Tools (SIFT) is an integrated framework for evaluating the security of an entire computer network on a single screen. The project attempts to address the need to discover undetected security incidents.
http://www.ncassr.org/projects/sift/

A case study/research paper providing detailed analysis of several anomalous network events to illustrate the techniques for examining alerts and logs generated by a network intrusion detection system.
http://www.zeltser.com/intrusion-detection-analysis/