19th Annual Computer Security Applications Conference (ACSAC '03)
Experimenting with a Policy-Based HIDS Based on an Information Flow Control Model
Las Vegas, Nevada
December 08-December 12
ISBN: 0-7692-2041-3
In [1], we proposed a model for policy-based intrusion detection, based on information flow control. In the present paper, we show its applicability and effectiveness on a standard OS. We present results of two set of experiments, one carried out in a completely controlled environment, the other on an operational server with real network traffic. Our results results show that the model fulfills its goals and serves as a successful runtime policy-based intrusion detector.
Citation:
Jacob Zimmerman, Ludovic M?, Christophe Bidan, "Experimenting with a Policy-Based HIDS Based on an Information Flow Control Model," acsac, pp.364, 19th Annual Computer Security Applications Conference (ACSAC '03), 2003