Visible to the public Diversity-based Detection of Security Anomalies

TitleDiversity-based Detection of Security Anomalies
Publication TypeConference Paper
Year of Publication2014
AuthorsVenkatakrishnan, Roopak, Vouk, Mladen A.
Conference NameProceedings of the 2014 Symposium and Bootcamp on the Science of Security
PublisherACM
Conference LocationRaleigh, NC, USA
ISBN Number978-1-4503-2907-1
KeywordsACM CCS, attack detection, CPS Technologies, cyber security, diversity, Foundations, Intrusion Detection Systems, Intrusion/Anomaly Detection and Malware Mitigation, redundancy in security, science of security, Systems Engineering, Testing, Validation and Verification, web services
Abstract

Detecting and preventing attacks before they compromise a system can be done using acceptance testing, redundancy based mechanisms, and using external consistency checking such external monitoring and watchdog processes. Diversity-based adjudication, is a step towards an oracle that uses knowable behavior of a healthy system. That approach, under best circumstances, is able to detect even zero-day attacks. In this approach we use functionally equivalent but in some way diverse components and we compare their output vectors and reactions for a given input vector. This paper discusses practical relevance of this approach in the context of recent web-service attacks.

URLhttp://doi.acm.org/10.1145/2600176.2600205
DOI10.1145/2600176.2600205
Citation KeyVenkatakrishnan:2014:DDS:2600176.2600205