A Progress Report on UNICOS Misuse Detection at Los Alamos

نویسندگان

  • Joseph L. Thompson
  • Kathleen A. Jackson
  • Cathy A. Stallings
  • Dennis D. Simmonds
  • Christine L.B. Siciliano
  • Georgia A. Pedicini
چکیده

An effective method for detecting computer misuse is the automatic monitoring and analysis of on-line user activity. During the past year, Los Alamos 1 enhanced its Network Anomaly Detection and Intrusion Reporter (NADIR) to include analysis of user activity on Los Alamos' UNICOS Crays. In near real-time, NADIR compares user activity to historical profiles and tests activity against expert rules. The expert rules express Los Alamos' security policy and define improper or suspicious behavior. NADIR reports suspicious behavior to security auditors and provides tools to aid in follow-up investigations. This paper describes the implementation to date of the UNICOS component of NADIR, along with our operational experiences and future plans for the system.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Opportunity Scheduling: An Unfair CPU Scheduler for UNICOS

Fair Share is the standard scheduling algorithm used for political resource control on large, multi-user UNIX systems. Promising equity, Fair Share has instead delivered frustration to its Los Alamos UNICOS users, who perceive misallocations of interactive response within a system of unreasonable complexity. This paper reviews the design of the Kay/Lauder Fair Share system, as well as its Cray ...

متن کامل

Quantum Detection and Invisibility in Coherent Nanostructures

J. Fransson, ∗ H. C. Manoharan, 3, † and A. V. Balatsky 5 Department of Physics and Materials Science, Uppsala University, Box 534, SE-6.551 21 Uppsala, Sweden Department of Physics, Stanford University, Stanford, CA 94305, USA Stanford Institute for Materials and Energy Sciences, Stanford University, Stanford, CA 94305, USA Theoretical Division, Los Alamos National Laboratory, Los Alamos, NM 6...

متن کامل

CCSM Polar Climate

The Polar Climate Working Group met in Santa Fe, New Mexico, to hear about new climate modeling studies and progress in model development. Several people from Los Alamos National Laboratory participated, who otherwise would not have attended. The meeting was sponsored jointly by the National Center for Atmospheric Research, the Climate, Ocean and Sea Ice Modeling Project at Los Alamos, and the ...

متن کامل

Detection of Aliasing in Persistent Signals

We explain why aliasing can be detected in a generic temporallysampled stationary signal process. We then define a concept of stationarity that makes sense for single waveforms. (This is done without assuming that the waveform is a sample path of some underlying stochastic process.) We show how to use this concept to detect aliasing in sampled waveforms. The constraint that must be satisfied to...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1997