A Progress Report on UNICOS Misuse Detection at Los Alamos
نویسندگان
چکیده
An effective method for detecting computer misuse is the automatic monitoring and analysis of on-line user activity. During the past year, Los Alamos 1 enhanced its Network Anomaly Detection and Intrusion Reporter (NADIR) to include analysis of user activity on Los Alamos' UNICOS Crays. In near real-time, NADIR compares user activity to historical profiles and tests activity against expert rules. The expert rules express Los Alamos' security policy and define improper or suspicious behavior. NADIR reports suspicious behavior to security auditors and provides tools to aid in follow-up investigations. This paper describes the implementation to date of the UNICOS component of NADIR, along with our operational experiences and future plans for the system.
منابع مشابه
Opportunity Scheduling: An Unfair CPU Scheduler for UNICOS
Fair Share is the standard scheduling algorithm used for political resource control on large, multi-user UNIX systems. Promising equity, Fair Share has instead delivered frustration to its Los Alamos UNICOS users, who perceive misallocations of interactive response within a system of unreasonable complexity. This paper reviews the design of the Kay/Lauder Fair Share system, as well as its Cray ...
متن کاملQuantum Detection and Invisibility in Coherent Nanostructures
J. Fransson, ∗ H. C. Manoharan, 3, † and A. V. Balatsky 5 Department of Physics and Materials Science, Uppsala University, Box 534, SE-6.551 21 Uppsala, Sweden Department of Physics, Stanford University, Stanford, CA 94305, USA Stanford Institute for Materials and Energy Sciences, Stanford University, Stanford, CA 94305, USA Theoretical Division, Los Alamos National Laboratory, Los Alamos, NM 6...
متن کاملCCSM Polar Climate
The Polar Climate Working Group met in Santa Fe, New Mexico, to hear about new climate modeling studies and progress in model development. Several people from Los Alamos National Laboratory participated, who otherwise would not have attended. The meeting was sponsored jointly by the National Center for Atmospheric Research, the Climate, Ocean and Sea Ice Modeling Project at Los Alamos, and the ...
متن کاملDetection of Aliasing in Persistent Signals
We explain why aliasing can be detected in a generic temporallysampled stationary signal process. We then define a concept of stationarity that makes sense for single waveforms. (This is done without assuming that the waveform is a sample path of some underlying stochastic process.) We show how to use this concept to detect aliasing in sampled waveforms. The constraint that must be satisfied to...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 1997