Yu-Sung Wu

dblp:39/5416 · DBLP profile ↗
← Back
26ranked-venue papers
5as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 4 first-author · 5 since 2021Systems, architecture and hardware · 7 · 3 first-authorSoftware engineering, systems software and programming languages · 5 · 1 since 2021Computer networks · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Mitigating Attacks on Web Applications via Fine-Grained Adaptive Control-Flow Integrity
abstract
While control-flow integrity (CFI) has been extensively applied to binary programs to ensure correct code execution, its application to web applications remains largely at the research stage. A key challenge lies in the inherent flexibility of web application programming and the extensive customizations it allows, which make optimizations based on static code analysis far less effective. To achieve practical performance, existing systems are limited to coarse-grained control-flow integrity, which leaves in trinsic detection blind spots. We propose fine-grained adaptive control-flow integrity (fgaCFI), the first web application CFI system that achieves basic-block level CFI with practical performance overhead. The Lightweight Dynamic Bytecode Monitor (LDBM) prototype, targeting PHP-based applications, supports three CFI monitoring granularity levels and adjustable monitoring scopes. Our results showed that basic-block level CFI achieved 100% detection coverage, outperforming function-level CFI with 83.33% detection coverage and request-level CFI with 58.33% detection coverage. By adapting to the uneven distribution of vulner abilities in the software modules, LDBM was able to maintain an 8.77% performance overhead on average.
Min-Chieh Wu, Yu-Sung Wu
IEEE Trans. Dependable Secur. Comput.2
2026 Suppressing False Positives in Web Application Firewalls With Program Trace Anomaly Detection
abstract
Web Application Firewalls (WAFs) have become the standard line of defense against web security attacks in production systems. However, due to the diverse and continuously evolving nature of web applications, WAF detection rules (or models) must remain sufficiently generic to accommodate attack variants and reduce maintenance costs, resulting in a substantial number of false positives. We propose program-trace-based anomaly detection as a means to suppress the false positives. Our prototype, TraceSense, analyzes the control flow of PHP-based web applications at adjustable granularity levels to detect attacks without re lying on manually crafted rules. The evaluation based on real world Common Vulnerabilities and Exposures (CVEs) demonstrates that TraceSense can accurately identify successful at tacks—comparable to rule-based WAFs—while reliably ignoring unsuccessful attacks that would trigger false positives in conventional systems. The alerts from program-trace-based anomaly detection are inherently self-explanatory. System administrators can use the built-in visualization tool to dismiss residual false positives and investigate unknown vulnerabilities.
Min-Chieh Wu, Yu-Wei Liao, Yu-Sung Wu
IEEE Trans. Reliab.3
2025 Poster: High-Fidelity and Contextual User Activity Memory Forensics
abstract
Retrieving application user activities from a memory dump has traditionally been a labor-intensive process, due to both the sheer volume of memory data and the complexity of opaque data structures. We introduce RAM-Weaver, a system that enables contextual querying of user activities from application memory dump files. RAM-Weaver distills essential information from raw dumps and leverages large language models (LLMs) to navigate opaque data structures and support interactive queries. This distillation process can reduce the data volume by up to 99.9% and improve the signal-to-noise ratio by nearly 37 dB, making it feasible to run on smaller, offline models. When combined with full-scale, cloud-hosted models, RAM-Weaver can retrieve user activity data with exceptionally high accuracy.
Min-Chieh Wu, Jui-An Chang, Yu-Sung Wu
CCS3
2025 Enhancing can security with ML-based IDS: Strategies and efficacies against adversarial attacks
Ying-Dar Lin, Wei-Hsiang Chan, Yuan-Cheng Lai, Chia-Mu Yu, Yu-Sung Wu, Wei-Bin Lee
Comput. Secur.5
2024 Neural Network-based Functional Degradation for Cyber-Physical Systems
abstract
From gimmicky IoT devices to self-driving cars, cyber-physical systems have become increasingly accessible to the masses. As these systems interact intimately with the physical world, failures in the systems can lead to severe, potentially life-threatening damage. Classical cyber-physical systems, such as aircraft flight control, employ dedicated redundancies for fault tolerance. However, a more flexible and cost-effective approach to redundancy is needed as cyber-physical systems become more versatile and expand to the consumer market. In this work, we explore the synthesis of redundancies for program functionalities with neural network models. The models are trained with the data from normal program executions and will be deployed to supplant the original program functionalities when failures occur. We have tested the prototype on representative cyber-physical systems, including ArduPilot and OpenPilot. The evaluation results indicate that the approach can synthesize redundancy models for both numerical and logical programs. We also demonstrate that the redundancy models can effectively avoid bugs and security vulnerabilities in the original programs.
Zheng-Hong Huang, Yu-Sung Wu, Ying-Dar Lin, Chia-Mu Yu, Wei-Bin Lee
QRS2
2024 Reliability Engineering in a Time of Rapidly Converging Technologies
abstract
The convergence of technologies is happening across various aspects, such as communication, computing, medicine, and transportation. The smartphone is a perfect example of convergence, packing features, such as a camera, GPS, artificial intelligence, and Internet connectivity into one sleek device. Autonomous driving is another good example. In a time of rapidly converging technologies, reliability engineering must take into account the potential for cyber threats, the need for cyber trust, the importance of cyber security, and the criticality of cyber resilience. In this way, reliability engineers can ensure the confidentiality, integrity, and availability of computer systems and networks in the face of evolving threats and changing technologies. In this article, we introduce the challenges and current progress of reliability engineering in emerging technologies, including practices and applications of cyber trust and security, AI-empowered autonomous driving systems, modern mobile networks, blockchains and distributed ledger technologies, prognostic and health management, integrated circuit and hardware, and enterprise cybersecurity and threat hunting.
Shiuh-Pyng Shieh, Jeffrey M. Voas, Phillip A. Laplante, Jason W. Rupe, Christian K. Hansen, Yu-Sung Wu, Yi-Ting Chen 0001, Chi-Yu Li 0001, Kai-Chiang Wu
IEEE Trans. Reliab.6
2023 Pervasive Micro Information Flow Tracking
abstract
Detection of advanced security attacks that exploit zero-day vulnerabilities or application-specific logic loopholes has been challenging due to the lack of attack signatures or substantial deviations in the overall system behavior. One has to zoom in to the affected code regions and look for local anomalies distinguishable from the benign workload to detect such attacks. We proposepervasive micro information flow tracking(PerMIT) that realizes variable-level online dynamic information flow tracking (DIFT) as a means to detect the attacks. The system uses hardware virtualization extension to monitor access to taint source variables and performs asynchronous code emulation to infer the local information flow. We demonstrate that the pervasive micro information flow can sufficiently capture the attacks and incurs only a small overhead. Given the program source code, the system can further enrich the semantics of micro information flow by embedding the variable names. We have integrated the system with machine learning algorithms to demonstrate the effectiveness of anomaly detection for zero-day attacks with pervasive micro information flow.
Sanoop Mallissery, Kun-Yi Chiang, Chun-An Bau, Yu-Sung Wu
IEEE Trans. Dependable Secur. Comput.4
2022 In-Vivo Fuzz Testing for Network Services
abstract
Fuzz testing is typically carried out by running the target program and the fuzzing engine offline in a lab environment. The environment setup may depend on specialized test harness code to activate the target program and inject the test data. Also, due to the vast program state space, domain knowledge-dependent optimization is often needed in the environment setup to achieve reasonably efficient fuzz testing. We propose In-Vivo Fuzzing to alleviate the burdens by performing online fuzz testing on live programs. In-Vivo Fuzzing hooks I/O library calls in a live program to collect test seeds. Upon request, the In-Vivo Runtime will create a fork of the target program and carry out fuzz testing on the forked process. The runtime states from the live program provide a vantage point to start the fuzzing process, and the test seeds collected from the live workload also facilitate the generation of effective test inputs. We applied In-Vivo Fuzzing to network service programs and implemented a prototype on top of the AFL fuzzer. Experiment results indicate that In-Vivo Fuzzing can reach vulnerabilities in real-world programs much more quickly than the baseline. We also demonstrate the potential application of In-Vivo Fuzzing in detecting unknown attacks, where live attack states are captured and amplified through fuzz testing.
Wen-Yang Lai, Kun-Che Tsai, Che Chen, Yu-Sung Wu
SRDS4
2020 POSTER: Data Leakage Detection for Health Information System based on Memory Introspection
abstract
The abundance of highly sensitive personal information in the Health Information System (HIS) has made it a prime target of data breach attacks. However, securing the system with existing Data Leakage Prevention (DLP) solutions is difficult due to a lack of security perimeter and diverse composition of software components. We propose the use of hypervisor-based memory introspection for implementing data leakage detection in such an environment. The approach looks for the presence of sensitive raw data in the memory of both the client machines and the server machines, transcending the dependence of pre-existing security perimeters. It is inherently compatible with different types of application software and robust against transport or at-rest data encryption. A prototype has been built on the Bareflank hypervisor and the OpenEMR platform. The evaluation results confirmed the effectiveness of the approach.
Sanoop Mallissery, Min-Chieh Wu, Chun-An Bau, Guan-Zhang Huang, Chen-Yu Yang, Wei-Chun Lin, Yu-Sung Wu
AsiaCCS7
2018 Enforcing Enterprise Mobile Application Security Policy with Plugin Framework
abstract
The prevalent use of mobile applications in enterprise computing requires more stringent yet flexible enforcement of security policies on the mobile devices. Existing enforcement mechanisms such as mobile device management system focus on the management of device features and cannot cover the diverse security policies of enterprise applications precisely. We address the challenge by proposing a novel security policy enforcement system based on Plugin framework. The system provides fine-grained security policy enforcement at each library call site in an application. With root privilege (targeting company-owned devices), fine-grained enforcement can be applied to any application. Without root privilege (targeting BYOD devices), fine-grained enforcement can be applied to the applications installed via the enforcement system.
Pang-Yang Chu, Wei-Huan Lu, Jun-Wei Lin, Yu-Sung Wu
PRDC4
2018 Semantic Failover in Software-Defined Networking
abstract
Software-defined networking (SDN) eases the management of large-scale network by providing centralized and programmable control of a network. The centralization inevitably creates a single point of failure and requires the use of redundant controllers. However, due to the need for replicating the SDN application states, existing solutions tend to assume that the controllers are of the same type. This imposes an undesirable trade-off between cost and availability as each active controller would require a dedicated standby controller of the same type. We propose semantic failover to address the issue, which allows generic failover across any types of controllers. Semantic failover models the SDN application states from the control plane messages and restores the application states by invoking the northbound API on the standby controller. It is thereby not dependent on specific types of controllers. The prototype system was tested on real-world SDN controllers, and the evaluation results have demonstrated the potentials of semantic failover for both homogenous and heterogeneous controller pairs.
Shu-Wen Hsueh, Tung-Yueh Lin, Weng-Ian Lei, Patrick Ngai, Yu-Hang Sheng, Yu-Sung Wu
PRDC6
2018 Hypervisor-Based Sensitive Data Leakage Detector
abstract
Sensitive Data Leakage (SDL) is a major issue faced by organizations due to increasing reliance on data-driven decision-making. Existing Data Leakage Prevention (DLP) solutions are being challenged by the adoption of network transport encryption and the presence of privileged-mode malware designed to tamper with the DLP agent programs. We propose a novel DLP system called "HyperSweep" that uses Virtual Machine Memory Introspection (VMI) technology to inspect the memory content of a guest system for sensitive information. The approach is robust against both network transport encryption and malware that attack DLP agent programs. The HyperSweep prototype is implemented on top of the KVM hypervisor. Our experiments have confirmed its applicability to real-world applications, including web browsers, office applications, and social networking applications. The experiments also indicate moderate performance overhead from applying HyperSweep.
Shu-Hao Chang, Sanoop Mallissery, Chih-Hao Hsieh, Yu-Sung Wu
QRS4
2017 Application Execution Time Prediction for Effective CPU Provisioning in Virtualization Environment
abstract
Provisioning of hardware resources through virtual machines (VMs) has been widely used for supporting server consolidation and infrastructure-as-a-cloud computing. We propose NICBLE to support accurate CPU resource provisioning for application workload running on VMs. While CPU is essential for any application workload, not every workload requires the same level of CPU resource. The VM tenants may also have different expectations of application performance and preferences. NICBLE models the execution of an application workload and employs a simulation-based algorithm to predict the impact on application execution time for a hypothetical VM configuration change on the number of CPUs. One may use NICBLE to reason about whether changing the number of CPUs will significantly affect the application performance. We built the NICBLE prototype on top of the Xen hypervisor [1]. NICBLE does not require modification to the guest systems. The performance overhead on the guest system is negligible. Our evaluation indicates that NICBLE is able to provide accurate prediction with an average error rate of less than 15 percent for non-adaptive application workload.
Yu-Sung Wu, Yi-Yung Chen, Chieh-Min Wang, Yennun Huang
IEEE Trans. Parallel Distributed Syst.2
2016 Smartphone Virtualization
abstract
Virtualization plays a pivotal role in the success of cloud computing service models and is applied extensively in modern public and private data centers. However, its adoption on end user devices such as laptop/desktop computers and cell phones is relatively scarce, mainly because convincing use cases for client device virtualization have proven elusive so far. As smartphones emerge as the linchpin of everyday computing and communication for regular people and application download becomes a fact of life, the Bring Your Own Cloud (BYOD) problem, in which corporate employees connect their own smartphones to the corporate networks for office work, has put most enterprises in an unenvious position of making a difficult choice between corporate security and employee productivity. One effective solution to the BYOD problem is smartphone virtualization, which provides multiple virtual smartphones on a physical smartphone, and enables a user to use a highly secure but not so flexible virtual smartphone in the work environment and a less secure but more flexible virtual smartphone when outside the work environment. This paper describes the design and implementation of a comprehensive smartphone virtualization system called Brahma, which consists of a virtualized smartphone element and a virtual mobility infrastructure element, and presents the detailed evaluation results of the first Brahma prototype on a commercial smartphone.
Tzi-cker Chiueh, Houcheng Lin, Ares Chao, Anthony, Tan-Gen Wu, Chieh-Min Wang, Yu-Sung Wu
ICPADS7
2016 Network Performance Bottleneck Detection and Maximum Network Throughput Estimation for Datacenter Applications
abstract
For applications deployed in third-party datacenter environments to attain cost-effective performance, it requires precise provisioning of hardware resources such as assigning appropriate network bandwidth to an application. However, it is not always clear how much resource should be assigned to an application. In this work, we propose NBD (Network performance Bottleneck Detector) to detect the network bandwidth requirement of a datacenter application. NBD is fully transparent and does not require modification of applications. It correctly reports the required bandwidth of an application even when the preset network bandwidth is far below the required bandwidth. NBD employs a novel technique called network flow distortion for the estimation of application network bandwidth requirement. The evaluation results indicate that NBD is effective and only incurs mild performance overhead.
Patrick Ngai, Sung-Jer Lu, Yu-Sung Wu, Wei-Sheng Lim, Tung-Yueh Lin
QRS3
2015 Towards consistent software defined networking with logic programming
abstract
Software Defined Networking (SDN) allows the construction of virtual networks on top of a datacenter network infrastructure. However, the flexibility also increases the chance of inconsistencies in the network configurations caused by component failures, software bugs, or human errors. The inconsistencies may result in service outage or security policy violation. We propose a model-based verification system to check the consistency of a virtual network. The system models the requirements as logic constraints and extracts the configuration states of a virtual network. The configuration states are checked against the logic constraints by using a SMT solver[1]. The prototype system successfully detects various inconsistencies injected to the testbed and incurs reasonable amount of overheads.
Eric Lui, Yu-Sung Wu, Patrick Ngai, Tung-Yueh Lin, Shih-Yi Huang
APNOMS2
2014 Application dependency tracing for message oriented middleware
abstract
Software defined infrastructure greatly reduces the deployment cost of distributed applications. Many distributed applications employ message oriented middleware (MOM) for the integration of heterogeneous components and to achieve scalability and fault tolerance. The structure of a distributed application can be very complex. In addition, the asynchronous message delivery model of MOM further complicates the runtime behavior of a distributed application. To diagnose a faulty distributed application, one often needs to determine the dependences of its messages, and by extension, the dependences of its components. We propose Message Tracer to identify the message dependencies of a MOM-based distributed application. Message Tracer sniffs the network traffic of MOM and uses knowledge of message broker protocols to establish the dependencies. Message Tracer makes no assumption on the application threading model and incurs negligible performance overhead. Message Tracer correctly identified 95% of the dependencies for the common use cases and 75% of the dependencies when the system was under extreme stress.
Li-Juin Wu, Yu-Jui Cheng, Yu-Sung Wu, Houcheng Lin
APNOMS4
2014 Preserving user query privacy in cloud-based security services
abstract
Cloud-based security services become popular in protection against security attacks for resource-constrained end-user devices. With abundant hardware at the cloud and strong support by security professionals, cloud-based security services can provide better protection than traditional security moni toring agents. However, security services usually involve the inspection of private system states or user behavior, which should not be disclosed to an untrusted entity, such as a cloud service provider. Maintaining end-user privacy and allowing security services to work on the cloud seem contradictory. In this paper, we present a framework for building privacy-preserving cloud-based security services. The framework consists of an architecture for building cloud-based security services and a technique, called private signature filtering, to preserve end-user privacy. The framework supports security monitoring signatures whose correspondence with end-user device queries can be established through conjunction of keywords and numeric value ranges. The framework also allows a trusted middle layer to do a part of the security monitoring computation for the end-user device to reduce the computation overhead on the end-user device. We implement two prototype systems for the cloud-based network intrusion service and the cloud-based malicious URL detection service, to verify effectiveness of our design. The experimental results show that the framework can indeed ensure end-user privacy with acceptable performance overhead in a practical cloud-based security service setting.
Yen-Chung Chen, Yu-Sung Wu, Wen-Guey Tzeng
J. Comput. Secur.2
2014 Secure and transparent network traffic replay, redirect, and relay in a dynamic malware analysis environment
abstract
ABSTRACT Dynamic analysis is typically performed in a closed network environment to prevent the malware under analysis from attacking machines on the Internet. However, many of today's malwares require Internet connectivity to operate and to be thoroughly analyzed in a closed network environment. We propose a secure and transparent network environment that allows the malware in a dynamic analysis environment to have seemingly unrestricted Internet access in a secure manner. Our environment transparently dispatches malicious network traffic to compatible decoys while allowing harmless control traffic to have Internet access. We use 12 real‐world malware samples, which involve Internet connections, to evaluate the effectiveness of the proposed environment. The evaluation shows that the proposed environment can allow malware to exhibit more network activities than a closed network environment and can even outperform the baseline open network environment in some cases. In the meantime, Internet security is maintained by the dispatching of attack and propagation traffic to decoys inside the analysis environment. Copyright © 2013 John Wiley & Sons, Ltd.
Ying-Dar Lin, Tzung-Bi Shih, Yu-Sung Wu, Yuan-Cheng Lai
Secur. Commun. Networks3
2013 EagleEye: Towards mandatory security monitoring in virtualized datacenter environment
abstract
Virtualized datacenter (VDC) has become a popular approach to large-scale system consolidation and the enabling technology for infrastructure-as-a-service cloud computing. The consolidation inevitably aggregates the security threats once faced by individual systems towards a VDC, and a VDC operator should remain vigilant of the threats at all times. We envision the need for on-demand mandatory security monitoring of critical guest systems as a means to track and deter security threats that could jeopardize the operation of a VDC. Unfortunately, existing VDC security monitoring mechanisms all require pre-installed guest components to operate. The security monitoring would either be up to the discretion of individual tenants or require costly direct management of guest systems by the VDC operator. We propose the EagleEye approach for on-demand mandatory security monitoring in VDC environment, which does not depend on pre-installed guest components. We implement a prototype on-access anti-virus monitor to demonstrate the feasibility of the EagleEye approach. We also identify challenges particular to this approach, and provide a set of solutions meant to strengthen future research in this area.
Yu-Sung Wu, Pei-Keng Sun, Chun-Chi Huang, Sung-Jer Lu, Syu-Fang Lai, Yi-Yung Chen
DSN1
2009 Spam detection in voice-over-IP calls through semi-supervised clustering
abstract
In this paper, we present an approach for detection of spam calls over IP telephony called SPIT in VoIP systems. SPIT detection is different from spam detection in email in that the process has to be soft real-time, fewer features are available for examination due to the difficulty of mining voice traffic at runtime, and similarity in signaling traffic between legitimate and malicious callers. Our approach differs from existing work in its adaptability to new environments without the need for laborious and error-prone manual parameter configuration. We use clustering based on the call parameters, using optional user feedback for some calls, which they mark as SPIT or non-SPIT. We improve on a popular algorithm for semi-supervised learning, called MPCK-Means, to make it scalable to a large number of calls and operate at runtime. Our evaluation on captured call traces shows a fifteen fold reduction in computation time, with improvement in detection accuracy.
Yu-Sung Wu, Saurabh Bagchi, Navjot Singh 0001, Ratsameetip Wita
DSN1
2007 Automated adaptive intrusion containment in systems of interacting services
Yu-Sung Wu, Bingrui Foo, Yu-Chun Mao, Saurabh Bagchi, Eugene H. Spafford
Comput. Networks1
2005 ADEPTS: Adaptive Intrusion Response Using Attack Graphs in an E-Commerce Environment
abstract
Distributed systems with multiple interacting services, especially e-commerce systems, are suitable targets for malicious attacks because of the potential financial impact. Compared to intrusion detection, automated response has received relatively less attention. In this paper, we present the design of automated response mechanisms in an intrusion tolerant system called ADEPTS. Our focus is on enforcing containment in the system, thus localizing the intrusion and allowing the system to provide service, albeit degraded. ADEPTS uses a graph of intrusion goals, called I-GRAPH, as the underlying representation in the system. In response to alerts from an intrusion detection framework, ADEPTS executes algorithms to determine the spread of the intrusion and the appropriate responses to deploy. A feedback mechanism evaluates the success of a deployed response and uses that in guiding future choices. ADEPTS is demonstrated on a distributed e-commerce system and evaluated using a survivability metric.
Bingrui Foo, Yu-Sung Wu, Yu-Chun Mao, Saurabh Bagchi, Eugene H. Spafford
DSN2
2004 Fault Tolerant Energy Aware Data Dissemination Protocol in Sensor Networks
abstract
In this paper we present a data dissemination protocol for efficiently distributing data through a sensor network in the face of node and link failures. Our work is motivated by the SPIN protocol which uses metadata negotiation to minimize data transmissions. We propose a protocol called shortest path minded SPIN (SPMS) in which every node has a zone defined by its maximum transmission radius. A data source node advertises the availability of data to all the nodes in its zone. Any interested node requests the data and gets sent the data using multi-hop communication via the shortest path. The failure of any node in the path is detected and recovered using backup routes. We build simulation models to compare SPMS against SPIN. The simulation results show that SPMS reduces the delay over 10 times and consumes 30% less energy in the static failure free scenario. Even with the addition of mobility, SPMS outperforms SPIN by energy gains between 5% and 21%. An analytical model is also constructed to compare the two protocols under a simplified topology.
Gunjan Khanna, Saurabh Bagchi, Yu-Sung Wu
DSN3
2004 SCIDIVE: A Stateful and Cross Protocol Intrusion Detection Architecture for Voice-over-IP Environments
abstract
Voice-over-IP (VoIP) systems are gaining in popularity as the technology for transmitting voice traffic over IP networks. As the popularity of VoIP systems increases, they are being subjected to different kinds of intrusions some of which are specific to such systems and some of which follow a general pattern. VoIP systems pose several new challenges to intrusion detection system (IDS) designers. First, these systems employ multiple protocols for call management (e.g., SIP) and data delivery (e.g., RTP). Second, the systems are distributed in nature and employ distributed clients, servers and proxies. Third, the attacks to such systems span a large class, from denial of service to billing fraud attacks. Finally, the systems are heterogeneous and typically under several different administrative domains. In this paper, we propose the design of an intrusion detection system targeted to VoIP systems, called SCIDIVE (pronounced "Skydive"). SCIDIVE is structured to detect different classes of intrusions, including, masquerading, denial of service, and media stream-based attacks. It can operate with both classes of protocols that compose VoIP systems - call management protocols (CMP), e.g., SIP, and media delivery protocols (MDP), e.g., RTP. SCIDIVE proposes two abstractions for VoIP IDS - stateful detection and cross-protocol detection. Stateful detection denotes assembling state from multiple packets and using the aggregated state in the rule-matching engine. Cross protocol detection denotes matching rules that span multiple protocols. SCIDIVE is demonstrated on a sample VoIP system that comprises SIP clients and SIP proxy servers with RTP as the data delivery protocol. Four attack scenarios are created and the accuracy and the efficiency of the system evaluated with rules meant to catch these attacks.
Yu-Sung Wu, Saurabh Bagchi, Sachin Garg, Navjot Singh 0001, Timothy K. Tsai
DSN1
2003 Collaborative Intrusion Detection System (CIDS): A Framework for Accurate and Efficient IDS
abstract
We present the design and implementation of a collaborative intrusion detection system (CIDS) for accurate and efficient intrusion detection in a distributed system. CIDS employs multiple specialized detectors at the different layers - network, kernel and application - and a manager based framework for aggregating the alarms from the different detectors to provide a combined alarm for an intrusion. The premise is that a carefully designed and configured CIDS can increase the accuracy of detection compared to individual detectors, without a substantial degradation in performance. In order to validate the premise, we present the design and implementation of a CIDS which employs Snort, Libsafe, and a new kernel level IDS called Sysmon. The manager has a graph-based and a Bayesian network based aggregation method for combining the alarms to finally come up with a decision about the intrusion. The system is evaluated using a Web-based electronic store front application and under three different classes of attacks - buffer overflow, flooding and script-based attacks. The results show performance degradations compared to no detection of 3.9% and 6.3% under normal workload and a buffer overflow attack respectively. The experiments to evaluate the accuracy of the system show that the normal workload generates false alarms for Snort and the elementary detectors produce missed alarms. CIDS does not flag the false alarm and reduces the incidence of missed alarms to 1 of the 7 cases. CIDS can also be used to measure the propagation time of an intrusion which is useful in choosing an appropriate response strategy.
Yu-Sung Wu, Bingrui Foo, Yongguo Mei, Saurabh Bagchi
ACSAC1