Revised taxonomy for intrusion-detection systems

213Citations
Citations of this article
190Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Intrusion-detection systems aim at detecting attacks against computer systems and networks, or in general against information systems. Indeed, it is difficult to provide provably secure information systems and to maintain them in such a secure state during their lifetime and utilization. Sometimes, legacy or operational constraints do not even allow the definition of a fully secure information system. Therefore, intrusion-detection systems have the task of monitoring the usage of such systems to detect apparition of insecure states. They detect attempts and active misuse, either by legitimate users of the information systems or by external parties, to abuse their privileges or exploit security vulnerabilities. In a previous paper, we introduced a taxonomy of intrusion-detection systems that highlights the various aspects of this area. This paper extends the taxonomy beyond real-time intrusion detection to include additional aspects of security monitoring, such as vulnerability assessment.

Cite

CITATION STYLE

APA

Debar, H., Dacier, M., & Wespi, A. (2000). Revised taxonomy for intrusion-detection systems. Annales Des Telecommunications/Annals of Telecommunications, 55(7), 361–378. https://doi.org/10.1007/bf02994844

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free