LEADER 05422nam 2200649 450 001 996465483903316 005 20211008162602.0 010 $a3-540-87403-8 024 7 $a10.1007/978-3-540-87403-4 035 $a(CKB)1000000000490909 035 $a(SSID)ssj0000716637 035 $a(PQKBManifestationID)11488544 035 $a(PQKBTitleCode)TC0000716637 035 $a(PQKBWorkID)10718637 035 $a(PQKB)10662360 035 $a(DE-He213)978-3-540-87403-4 035 $a(MiAaPQ)EBC3063298 035 $a(MiAaPQ)EBC6511673 035 $a(Au-PeEL)EBL6511673 035 $a(OCoLC)288524346 035 $a(PPN)129062820 035 $a(EXLCZ)991000000000490909 100 $a20211008d2008 uy 0 101 0 $aeng 135 $aurnn|008mamaa 181 $ctxt 182 $cc 183 $acr 200 00$aRecent advances in intrusion detection $e11th international symposium, RAID 2008, Cambridge, MA, USA, September 15-17, 2008 : proceedings /$fRichard Lippmann, Engin Kirda, and Ari Trachtenberg (eds) 205 $a1st ed. 2008. 210 1$aBerlin, Germany ;$aNew York, New York :$cSpringer,$d[2008] 210 4$dİ2008 215 $a1 online resource (XIV, 424 p.) 225 1 $aSecurity and Cryptology ;$v5230 300 $aIncludes index. 311 $a3-540-87402-X 320 $aIncludes bibliographical references and index. 327 $aRecent Advances in Intrusion Detection -- Guest-Transparent Prevention of Kernel Rootkits with VMM-Based Memory Shadowing -- Countering Persistent Kernel Rootkits through Systematic Hook Discovery -- Malware Detection and Prevention -- Tamper-Resistant, Application-Aware Blocking of Malicious Network Connections -- A First Step towards Live Botmaster Traceback -- A Layered Architecture for Detecting Malicious Behaviors -- A Study of the Packer Problem and Its Solutions -- High Performance Intrusion Detection and Evasion -- Gnort: High Performance Network Intrusion Detection Using Graphics Processors -- Predicting the Resource Consumption of Network Intrusion Detection Systems -- High-Speed Matching of Vulnerability Signatures -- Web Application Testing and Evasion -- Swarm Attacks against Network-Level Emulation/Analysis -- Leveraging User Interactions for In-Depth Testing of Web Applications -- Model-Based Covert Timing Channels: Automated Modeling and Evasion -- Alert Correlation and Worm Detection -- Optimal Cost, Collaborative, and Distributed Response to Zero-Day Worms - A Control Theoretic Approach -- On the Limits of Payload-Oblivious Network Attack Detection -- Determining Placement of Intrusion Detectors for a Distributed Application through Bayesian Network Modeling -- A Multi-Sensor Model to Improve Automated Attack Detection -- Anomaly Detection and Network Traffic Analysis -- Monitoring SIP Traffic Using Support Vector Machines -- The Effect of Clock Resolution on Keystroke Dynamics -- A Comparative Evaluation of Anomaly Detectors under Portscan Attacks -- Advanced Network Fingerprinting -- Posters -- On Evaluation of Response Cost for Intrusion Response Systems -- WebIDS: A Cooperative Bayesian Anomaly-Based Intrusion Detection System for Web Applications (Extended Abstract) -- Evading Anomaly Detection through Variance Injection Attacks on PCA -- Anticipating Hidden Text Salting in Emails -- Improving Anomaly Detection Error Rate by Collective Trust Modeling -- Database Intrusion Detection and Response -- An Empirical Approach to Identify Information Misuse by Insiders (Extended Abstract) -- Page-Based Anomaly Detection in Large Scale Web Clusters Using Adaptive MapReduce (Extended Abstract) -- Automating the Analysis of Honeypot Data (Extended Abstract) -- Anomaly and Specification Based Cognitive Approach for Mission-Level Detection and Response -- Monitoring the Execution of Third-Party Software on Mobile Devices -- Streaming Estimation of Information-Theoretic Metrics for Anomaly Detection (Extended Abstract) -- Bots Behaviors vs. Human Behaviors on Large-Scale Communication Networks (Extended Abstract) -- Anomalous Taint Detection -- Deep Packet Inspection Using Message Passing Networks -- System Call API Obfuscation (Extended Abstract). 330 $aThis book constitutes the refereed proceedings of the 11th International Symposium on Recent Advances in Intrusion Detection, RAID 2008, held in Cambridge, MA, USA, in September 2008. The 20 revised full papers presented together with 16 revised poster papers were carefully reviewed and selected from 80 submissions. The papers are organized in topical sections on rootkit prevention, malware detection and prevention, high performance intrusion and evasion, Web application testing and evasion, alert correlation and worm detection, as well as anomaly detection and network traffic analysis. 410 0$aSecurity and Cryptology ;$v5230 606 $aInformation systems 606 $aComputer science 606 $aData encryption (Computer science) 615 0$aInformation systems. 615 0$aComputer science. 615 0$aData encryption (Computer science) 676 $a005.74 702 $aKirda$b Engin 702 $aTrachtenberg$b Ari 702 $aLippmann$b Richard 801 0$bMiAaPQ 801 1$bMiAaPQ 801 2$bMiAaPQ 906 $aBOOK 912 $a996465483903316 996 $aRecent Advances in Intrusion Detection$9772673 997 $aUNISA