The architecture of a network level intrusion detection system
- 15 August 1990
- report
- Published by Office of Scientific and Technical Information (OSTI)
Abstract
This paper presents the preliminary architecture of a network level intrusion detection system. The proposed system will monitor base level information in network packets (source, destination, packet size, and time), learning the normal patterns and announcing anomalies as they occur. The goal of this research is to determine the applicability of current intrusion detection technology to the detection of network level intrusions. In particular, the authors are investigating the possibility of using this technology to detect and react to worm programs.Keywords
This publication has 0 references indexed in Scilit: