Haystack: an intrusion detection system 论文

2003引用 295
Network Security and Intrusion DetectionInformation and Cyber SecuritySmart Grid Security and Resilience

摘要

Haystack is a prototype system for the detection of intrusions in multiuser US Air Force computer systems. Haystack reduces voluminous system audit trails to short summaries of user behavior, anomalous events, and security incidents. This is designed to help the system security officer detect and investigate intrusions, particularly by insiders (authorized users). Haystacks's operation is based on behavioral constraints imposed by security policies and on models of typical behavior for user groups and individual users.< <ETX xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">&gt;</ETX>

相关事件

暂无数据

相关文章

暂无数据