A Host-based Multi-layer Intrusion Detection Model and Its Detection Methods

蔡忠闽,彭勤科,管晓宏,孙国基
DOI: https://doi.org/10.3969/j.issn.1000-3428.2002.07.028
2002-01-01
Abstract:In this paper we present a multi-layer and defense-in-depth intrusion detection model for networked computer systems with a prototype. In this model, the operations on the protected computer system are monitored by four sensors from different viewpoints. The final judgement is made by combining the results of the individual sensors using information fusion techniques. It is demonstrated that an anomaly behavior can be more easily discovered and false alarms can be effectively reduced using our detection model. The methods to detect intrusions at different layers are also discussed using the experience gained in prototype realization.
What problem does this paper attempt to address?