Experiences with Specification Based Intrusion Detection
Intrusion Detection Approaches
Open Issues of
Specification-Based Approach
Pattern Language:
Regular Expression over Events (REE)
Specification Development
Methodology
Specifications customized
for
program groups
Application Specific Specifications
Tailoring Specifications
for an OS/Site
Offline Evaluation:
Effectiveness with
Normal Behavior Specifications
Addition of misuse specifications