PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
November 22, 2002327 citations

Execution monitoring of security-critical programs in distributed systems: a specification-based approach

View Full Paper
CKCalvin KoMRManfred RuschitzkaKLKarl Levitt

Key Points

Key points are not available for this paper at this time.

Abstract

We describe a specification-based approach to detect exploitations of vulnerabilities in security-critical programs. The approach utilizes security specifications that describe the intended behavior of programs and scans audit trails for operations that are in violation of the specifications. We developed a formal framework for specifying the security-relevant behavior of programs, on which we based the design and implementation of a real-time intrusion detection system for a distributed system. Also, we wrote security specifications for 15 Unix setuid root programs. Our system detects attacks caused by monitored programs, including security violations caused by improper synchronization in distributed programs. Our approach encompasses attacks that exploit previously unknown vulnerabilities in security-critical programs.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Ko et al. (2002) studied this question.

synapsesocial.com/papers/6a0f0bde06ecbe833448193fhttps://doi.org/10.1109/secpri.1997.601332
Ask AI
Helpful
Bookmark
Share
View Full Paper