On the feasibility of intrusion detection inside workstation disks

msra(2003)

引用 38|浏览52
暂无评分
摘要
Storage-based intrusion detection systems (IDSes) can be valuable tools in monitoring for and noti- fying administrators of malicious software executing on a host computer, including many common intrusion toolkits. This paper makes a case for implementing IDS functionality in the firmware of workstations' locally attached disks, on which the bulk of important system files typically reside. To evaluate the feasibility of this approach, we built a prototype disk-based IDS into a SCSI disk emulator. Experimental results from this prototype indicate that it would indeed be feasible, in terms of CPU and memory costs, to include IDS functionality in low-cost desktop disk drives.
更多
查看译文
关键词
firmware,computer viruses,intrusion detection,feasibility studies,intrusion detection system,ids,interfaces,computer security,prototypes,embedding
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要