USTAT: A Real-Time Intrusion Detection System for UNIX

  • Authors:
  • Koral Ilgun

  • Affiliations:
  • -

  • Venue:
  • SP '93 Proceedings of the 1993 IEEE Symposium on Security and Privacy
  • Year:
  • 1993

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents the design and implementationof a real-time intrusion detection tool, called Us-TAT', a State Transition Analysis Tool for UNIX. This is a UNIX-specific implementation of a generic designdeveloped by Phillip A. Porras and presented in [Porr92B] as STAT, State Transition Analysis TOOL State Transition Analysis is a new approach to representing computer penetrations. In STAT, a penetration is identified as a sequence of state changes that take the computer system from some initial state to a target compromised state.In this paper, the development of the first USTATprototype, which is for SunOS 4.1.1, is discussed. Us-TAT makes use of the audit trails that are collected bythe C2 Basic Security Module of Sun OS, and it keepstrack of only those critical actions that must occur forthe successful completion of the penetration. This approachdiffers from other rule-based penetration identificationtools that pattern match sequences of audit records.