The Kerf Toolkit For Intrusion Analysis

J Aslam, S Bratus, D Kotz,R Peterson,D Rus,B Tofel

IEEE Security and Privacy(2003)

引用 10|浏览1
暂无评分
摘要
Abstract We consider the problem of intrusion analysis and present the Kerf Toolkit , whose purpose is to provide an efficient and flexible infrastructure for the analysis of at - tacks The Kerf Toolkit includes a mechanism for se - curely recording host and network logging information for a network of workstations, a domain - specific language for querying this stored data, and an interface for viewing the results of such a query, providing feedback on these re - sults, and generating new queries in an iterative fashion We describe the architecture of Kerf, present examples to demonstrate the power of our query language, and discuss the performance of our implementation of this system
更多
查看译文
关键词
integrated front end,post-attack intrusion analysis,intrusion analysis,kerf toolkit,data-representation tool,system administrator,powerful correlation,query language,domain specific language,data structures
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要