loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
12th International Conference on Parallel and Distributed Systems - Volume 1 (ICPADS'06)
Research on Object-Storage-Based Intrusion Detection
Minneapolis, Minnesota
July 12-July 15
ISBN: 0-7695-2612-8
Youhui Zhang, Tsinghua University, China
Dongsheng Wang, Tsinghua University, China
Storage-based intrusion detection systems (IDS) can be valuable tools in monitoring for the intrusion on a host computer. However, because the traditional storage device works on the block-level while intrusion always happens on the file-level, this gap has to be erased by detection software, which is a hard and time-consuming task. To solve this problem and to accord with the trend of moving more processing power into storage, this paper presents a novel idea to design an IDS on object-based storage devices (OSD), and analyzes how the features of OSD can be used for intrusion detection (ID) and for violation responding. Moreover, the existing OSD standard is enhanced to own the new functions. Compared with the existing research on block-level storage devices, OSD-based ID is more straightforward for implementation. We build such a prototype based on the OSD reference implementation provided by Intel. Testing results show that the extra overhead introduced by ID is acceptable.
Citation:
Youhui Zhang, Dongsheng Wang, "Research on Object-Storage-Based Intrusion Detection," icpads, vol. 1, pp.68-78, 12th International Conference on Parallel and Distributed Systems - Volume 1 (ICPADS'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.