Storming Media: Pentagon Reports and DocumentsPentagon Reports: Fast. Definitive. Complete.     
New Account »
Forgot Password?
Advanced Search »

Newsletter
Unsubscribe »
Reports by Author

Jonathon T. Giffin


Click on the titles below to find US government-authored or -collected reports written by Jonathon T. Giffin

Total Results: 4 Results per page:
Sort by: Title Date Desc Pages Display:
An Architecture for Generating Semantics-Aware Signatures 2006 17 pages
Authors:  Vinod Yegneswaran; Jonathon T. Giffin; Paul Barford; Somesh Jha; WISCONSIN UNIV-MADISON DEPT OF COMPUTER SCIENCES
The full text of this report is available for sale.Identifying new intrusions and developing effective signatures that detect them is essential for protecting computer networks. We present Nemean, a system for automatic generation of intrusion signatures from honeynet packet traces. Our architecture is distinguished by its emphasis on a modular design framework that encourages independent development and modification of system components and protocol semantics awareness which allows for construction of signatures that greatly reduce false alarms. The building blocks ...


Formalizing Sensitivity in Static Analysis for Intrusion Detection 2006 16 pages
Authors:  Henry H. Feng; Jonathon T. Giffin; Yong Huang; Somesh Jha; Wenke Lee; Barton P. Miller; MASSACHUSETTS UNIV AMHERST DEPT OF ELECTRICAL AND COMPUTER ENGINEERING
The full text of this report is available for sale.A key function of a host-based intrusion detection system is to monitor program execution. Models constructed using static analysis have the highly desirable feature that they do not produce false alarms; however, they may still miss attacks. Prior work has shown a trade-off between efficiency and precision. In particular, the more accurate models based upon pushdown automata (PDA) are very inefficient to operate due to non-determinism in stack activity. In ...


Automated Discovery of Mimicry Attacks 2006 21 pages
Authors:  Jonathon T. Giffin; Somesh Jha; Barton P. Miller; WISCONSIN UNIV-MADISON DEPT OF COMPUTER SCIENCES
The full text of this report is available for sale.Model-based anomaly detection systems restrict program execution by a predefined model of allowed system call sequences. These systems are useful only if they detect actual attacks. Previous research developed manually-constructed mimicry and evasion attacks that avoided detection by hiding a malicious series of system calls within a valid sequence allowed by the model. Our work helps to automate the discovery of such attacks. We start with two models: a program ...


An Auctioning Reputation System Based on Anomaly Detection 2005 11 pages
Authors:  Shai Rubin; Mihai Christodorescu; Vinod Ganapathy; Jonathon T. Giffin; Louis Kruger; Hao Wang; WISCONSIN UNIV-MADISON DEPT OF COMPUTER SCIENCES
The full text of this report is available for sale.Existing reputation systems used by online auction houses do not address the concern of a buyer shopping for commodities finding a good bargain. These systems do not provide information on the practices adopted by sellers to ensure profitable auctions. These practices may be legitimate, like imposing a minimum starting bid on an auction, or fraudulent, like using colluding bidders to inflate the final price in a practice known as shilling. ...


Total Results: 4 Results per page: