Handbook of Information Security: Threats, Vulnerabilities, Prevention, Detection, and Management, Volume 3
by Hossein Bidgoli
Host-Based Intrusion Detection Systems
Giovanni Vigna, Reliable Software Group
Christopher Kruegel, Technical University, Vienna, Austria
Operating System–Level Intrusion Detection
Specification-Based Approaches
Application-Level Intrusion Detection
Specification-Based Approaches
Host-Based IDSs versus Network-Based IDSs
INTRODUCTION
Intrusion detection (Crothers, 2002; Schultz, Endorf, & Mellander, 2003) is the process of identifying and responding to suspicious activities targeted at computing and communication resources. An intrusion detection system (IDS) monitors and collects data from a target system that should be protected, processes and correlates the gathered information, and initiates responses when evidence of an intrusion is detected. Depending on their source of input, IDSs can be classified into network-based systems and host-based systems.
Network-based intrusion detection systems (NIDSs) collect input data by monitoring network traffic (e.g., packets captured by network interfaces in promiscuous mode). Host-based intrusion detection systems (HIDSs), on the other hand, rely on events collected by the hosts they monitor.
HIDSs can be classified based on the type of audit data they analyze or based on the techniques used to analyze their ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access