Matches in SemOpenAlex for { <https://semopenalex.org/work/W2171133738> ?p ?o ?g. }
Showing items 1 to 97 of
97
with 100 items per page.
- W2171133738 endingPage "697" @default.
- W2171133738 startingPage "671" @default.
- W2171133738 abstract "A network device is considered compromised when one of its security mechanisms is defeated by an attacker. For many networks, an attacker can compromise many devices before being discovered. However, investigating devices for compromise is costly and time-consuming, making it difficult to investigate all, or even most, of a network's devices. Further, investigation can yield false-negative results. This paper describes an intrusion–detection (ID) technique for incident-response. During an attack, the attacker reveals information about himself and about network vulnerabilities. This information can be used to identify the network's likely compromised devices (LCDs). Knowledge of LCDs is useful when limited resources allow only some of the network's devices to be investigated. During an on-going attack, knowledge of LCDs is also useful for tactical planning. The ID technique is based on the US military's battlefield-intelligence process. Models are constructed of the network, as the battlespace. Also, models are constructed of the attacker’s capabilities, intentions, and courses-of-action. The Economics of Crime, a theory which explains criminal behavior, is used to model the attacker's courses-of-action. The models of the network and the attacker are used to identify the devices most likely to be compromised." @default.
- W2171133738 created "2016-06-24" @default.
- W2171133738 creator A5005760849 @default.
- W2171133738 creator A5007531890 @default.
- W2171133738 creator A5011947197 @default.
- W2171133738 creator A5031854304 @default.
- W2171133738 creator A5036349955 @default.
- W2171133738 creator A5041210739 @default.
- W2171133738 creator A5042832834 @default.
- W2171133738 date "2000-10-01" @default.
- W2171133738 modified "2023-09-24" @default.
- W2171133738 title "Intrusion-detection for incident-response, using a military battlefield-intelligence process" @default.
- W2171133738 cites W1502173919 @default.
- W2171133738 cites W1601929078 @default.
- W2171133738 cites W2066716552 @default.
- W2171133738 cites W2158390457 @default.
- W2171133738 cites W4244496119 @default.
- W2171133738 doi "https://doi.org/10.1016/s1389-1286(00)00142-0" @default.
- W2171133738 hasPublicationYear "2000" @default.
- W2171133738 type Work @default.
- W2171133738 sameAs 2171133738 @default.
- W2171133738 citedByCount "21" @default.
- W2171133738 countsByYear W21711337382013 @default.
- W2171133738 countsByYear W21711337382014 @default.
- W2171133738 countsByYear W21711337382015 @default.
- W2171133738 countsByYear W21711337382016 @default.
- W2171133738 countsByYear W21711337382018 @default.
- W2171133738 countsByYear W21711337382021 @default.
- W2171133738 crossrefType "journal-article" @default.
- W2171133738 hasAuthorship W2171133738A5005760849 @default.
- W2171133738 hasAuthorship W2171133738A5007531890 @default.
- W2171133738 hasAuthorship W2171133738A5011947197 @default.
- W2171133738 hasAuthorship W2171133738A5031854304 @default.
- W2171133738 hasAuthorship W2171133738A5036349955 @default.
- W2171133738 hasAuthorship W2171133738A5041210739 @default.
- W2171133738 hasAuthorship W2171133738A5042832834 @default.
- W2171133738 hasConcept C111919701 @default.
- W2171133738 hasConcept C121332964 @default.
- W2171133738 hasConcept C127413603 @default.
- W2171133738 hasConcept C144024400 @default.
- W2171133738 hasConcept C145804949 @default.
- W2171133738 hasConcept C146978453 @default.
- W2171133738 hasConcept C182590292 @default.
- W2171133738 hasConcept C195244886 @default.
- W2171133738 hasConcept C2779669469 @default.
- W2171133738 hasConcept C2780791683 @default.
- W2171133738 hasConcept C2781438671 @default.
- W2171133738 hasConcept C35525427 @default.
- W2171133738 hasConcept C36289849 @default.
- W2171133738 hasConcept C38652104 @default.
- W2171133738 hasConcept C41008148 @default.
- W2171133738 hasConcept C41065033 @default.
- W2171133738 hasConcept C46355384 @default.
- W2171133738 hasConcept C62520636 @default.
- W2171133738 hasConcept C95457728 @default.
- W2171133738 hasConcept C98045186 @default.
- W2171133738 hasConceptScore W2171133738C111919701 @default.
- W2171133738 hasConceptScore W2171133738C121332964 @default.
- W2171133738 hasConceptScore W2171133738C127413603 @default.
- W2171133738 hasConceptScore W2171133738C144024400 @default.
- W2171133738 hasConceptScore W2171133738C145804949 @default.
- W2171133738 hasConceptScore W2171133738C146978453 @default.
- W2171133738 hasConceptScore W2171133738C182590292 @default.
- W2171133738 hasConceptScore W2171133738C195244886 @default.
- W2171133738 hasConceptScore W2171133738C2779669469 @default.
- W2171133738 hasConceptScore W2171133738C2780791683 @default.
- W2171133738 hasConceptScore W2171133738C2781438671 @default.
- W2171133738 hasConceptScore W2171133738C35525427 @default.
- W2171133738 hasConceptScore W2171133738C36289849 @default.
- W2171133738 hasConceptScore W2171133738C38652104 @default.
- W2171133738 hasConceptScore W2171133738C41008148 @default.
- W2171133738 hasConceptScore W2171133738C41065033 @default.
- W2171133738 hasConceptScore W2171133738C46355384 @default.
- W2171133738 hasConceptScore W2171133738C62520636 @default.
- W2171133738 hasConceptScore W2171133738C95457728 @default.
- W2171133738 hasConceptScore W2171133738C98045186 @default.
- W2171133738 hasIssue "4" @default.
- W2171133738 hasLocation W21711337381 @default.
- W2171133738 hasOpenAccess W2171133738 @default.
- W2171133738 hasPrimaryLocation W21711337381 @default.
- W2171133738 hasRelatedWork W101622072 @default.
- W2171133738 hasRelatedWork W1484162745 @default.
- W2171133738 hasRelatedWork W2171133738 @default.
- W2171133738 hasRelatedWork W2371145078 @default.
- W2171133738 hasRelatedWork W2382652000 @default.
- W2171133738 hasRelatedWork W2945728441 @default.
- W2171133738 hasRelatedWork W4288357153 @default.
- W2171133738 hasRelatedWork W4376624795 @default.
- W2171133738 hasRelatedWork W8007349 @default.
- W2171133738 hasRelatedWork W238225969 @default.
- W2171133738 hasVolume "34" @default.
- W2171133738 isParatext "false" @default.
- W2171133738 isRetracted "false" @default.
- W2171133738 magId "2171133738" @default.
- W2171133738 workType "article" @default.