Expression and deployment of reaction policies - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2008

Expression and deployment of reaction policies

Résumé

Current prevention techniques provide restrictive responses that may take a local reaction in a limited information system infrastructure. In this paper, an in depth and comprehensive approach is introduced for responding to intrusions in an efficient way. This approach considers not only the threat and the architecture of the monitored information system, but also the security policy. The proposed reaction workflow links the lowest level of the information system corresponding to intrusion detection mechanisms, including misuse and anomaly techniques, and access control techniques with the higher level of the security policy. This reaction workflow evaluates the intrusion alerts at three different levels, it then reacts against threats with appropriate counter measures in each level accordingly.
Fichier principal
Vignette du fichier
latex8.pdf (571.54 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00540778 , version 1 (29-11-2010)

Identifiants

Citer

Frédéric Cuppens, Nora Cuppens-Bouhlahia, Wael Kanoun, Yacine Bouzida, Aurélien Croissant. Expression and deployment of reaction policies. SITIS : 4th IEEE Conference on Signal Image Technology and Internet Based Systems (SITIS'08), Nov 2008, Bali, Indonesia. pp.118 - 127, ⟨10.1109/SITIS.2008.96⟩. ⟨hal-00540778⟩
199 Consultations
195 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More