An intrusion-detection system based on the Teiresias pattern-discovery algorithm. Wespi, A., Dacier, M., & Debar, H. In Gattiker, U. E., Pedersen, P., & Petersen, K., editors, Proceedings of EICAR 1999, 1999. European Institute for Computer Antivirus Research (EICAR). 00064 bibtex: wespi1999intrusion
doi  abstract   bibtex   
This paper addresses the problem of creating a pattern table that can be used to model the normal behavior of a given process. The model can be used for intrusion-detection purposes. So far, most of the approaches proposed have been based on fixed-length patterns, although variable-length patterns seem to be more naturally suited to model the normal process behavior. We have developed a technique to build tables of variable-length patterns. This technique is based on Teiresias, an algorithm initially developed for the discovery of rigid patterns in unaligned biological sequences. We evaluate the quality of our technique in a testbed environment and compare it with techniques based on fixed-length patterns.
@inproceedings{ wespi_intrusion-detection_1999,
  title = {An intrusion-detection system based on the {Teiresias} pattern-discovery algorithm},
  doi = {10.1.1.23.6768},
  abstract = {This paper addresses the problem of creating a pattern table that can be used to model the normal behavior of a given process. The model can be used for intrusion-detection purposes. So far, most of the approaches proposed have been based on fixed-length patterns, although variable-length patterns seem to be more naturally suited to model the normal process behavior. We have developed a technique to build tables of variable-length patterns. This technique is based on Teiresias, an algorithm initially developed for the discovery of rigid patterns in unaligned biological sequences. We evaluate the quality of our technique in a testbed environment and compare it with techniques based on fixed-length patterns.},
  booktitle = {Proceedings of {EICAR} 1999},
  publisher = {European Institute for Computer Antivirus Research (EICAR)},
  author = {Wespi, Andreas and Dacier, Marc and Debar, Hervé},
  editor = {Gattiker, U. E. and Pedersen, P. and Petersen, K.},
  year = {1999},
  note = {00064 bibtex: wespi1999intrusion}
}

Downloads: 0