17th Annual Computer Security Applications Conference (ACSAC'01)
Watcher: The Missing Piece of the Security Puzzle
New Orleans, Lousiana
December 10-December 14
ISBN: 0-7695-1405-7
Modern intrusion detection systems are comprised of three basically different approaches, host based, network based, and a third relatively recent addition called procedural based detection. The first two have been extremely popular in the commercial market for a number of years now because they are relatively simple to use, understand and maintain. However, they fall prey to a number of shortcomings such as scaling with increased traffic requirements, use of complex and false positive prone signature databases, and their inability to detect novel intrusive attempts. The procedural based intrusion detection systems represent a great leap forward over current security technologies by addressing these and other concerns. This paper presents an overview of our work in creating a true procedural Disallowed Operational Anomaly (DOA) system.