CylantSecure for Linux.
"..."
Most of the current focus of intrusion detection systems look either at the input to the system (e.g., network connections, attack signatures) or the output from the system (file checksums, etc.).
CylantSecure looks instead at the behavior of the system itself, producing a model for what the "normal" behavior of the CPU is, when in production use, and therefore detecting "abnormal" behavior and actively dropping connections or terminating processes that display abnormal behavior.
[^] # Re: proposition de frlinux (trop tard alors je la mets ici)
Posté par cliklik . En réponse à la dépêche Histoire d'une attaque par Deni de Service. Évalué à 1.
http://lwn.net/2001/0503/security.php3(...)
CylantSecure for Linux.
"..."
Most of the current focus of intrusion detection systems look either at the input to the system (e.g., network connections, attack signatures) or the output from the system (file checksums, etc.).
CylantSecure looks instead at the behavior of the system itself, producing a model for what the "normal" behavior of the CPU is, when in production use, and therefore detecting "abnormal" behavior and actively dropping connections or terminating processes that display abnormal behavior.