Telcordia Technologies AR Greenhouse
vine endAR HomeBackFeedbackTelcordia Homevine end

Selected Papers by Thomas F. Bowen


On Preventing Intrusions by Process Behavior Monitoring
Authors:
R. Sekar, T. Bowen and M. Segal
Published:
On Preventing Intrusions by Process Behavior Monitoring
Abstract:

Society's increasing reliance on networked information systems to support critical infrastructures has prompted interest in making the information systems survivable, so that they continue to perform critical functions even in the presence of vulnerabilities susceptible to malicious attacks. To enable vulnerable systems to survive attacks, it is necessary to detect attacks and isolate failures resulting from attacks before they damage the system by impacting functionality, performance or security. The key research problems in this context in-clude:

  • detecting in-progress attacks before they cause damage, as opposed to detecting attacks after they have succeeded,
  • localizing and/or minimizing damage by isolating attacked components in real-time, and
  • tracing the origin of attacks.

We address the detection problem by real-time event monitoring and comparison against events known to be unacceptable. Real-time detection differentiates our approach from previous works that focus on intrusion detection by post-attack evidence analysis. We address the isolation and tracing problems by supporting automatic initiation of reactions. Reactions are programs that we develop to respond to attacks. A reaction's primary goal is to isolate compromised components and prevent them from damaging other components. A reaction's secondary goal is to aid in tracing the origin of attack, e.g., by providing an illusion of success to the attackers (enticing them to continue the attack) while ensuring that the attack causes no damage.

Our approach to detecting attacks is based on specifying permissible process behaviors as logical assertions on sequences of system calls and conditions on the values of system call arguments. We compile the specifications into finite state automata for efficient runtime detection of deviations from the specified (and hence permissible) behavior. We seamlessly integrate detection and reaction by designing our specification language to also allow specification of reactions.

Distributed Control of a Local Broadband Switch
Authors:
T. F. Bowen
Published:
ICC/89 Boston, Ma, June 11-14 1989
A Scalable Database Architecture for Network Services
Authors:
T. F. Bowen, G. Gopal, G. E. Herman and W. H. Mansfield
Published:
IEEE Communications Magazine, vol. 29, no. 1, pp. 52-59, January 1991.
A Scaleable Database Architecture for Network Services
Authors:
T. F. Bowen, G. Gopal, G. Herman, W. H. Mansfield
Published:
Proceedings of the 8th International Switching Symposium, May 1990.
The Datacycle Architecture
Authors:
T. F. Bowen, G. Gopal, G. Herman, T. Hickey, K. C. Lee, W. H. Mansfield, J. Raitz and A. Weinrib
Published:
Communications of the ACM, December 1992, Vol. 35, No. 12.
Feature interaction problem in telecommunications systems
Authors:
F. S. Dworak, T. F. Bowen, D. H. Chow, G. E. Herman, N. Griffeth and Y.-J. Lin
Published:
Proceedings of the Seventh International Conference on Software Engineering for Telecommunication Switching Systems, July 1989.

Professional Bio

 

Home Back Top of Page Feedback www.telcordia.com
 
     Last Updated:
© 1999 - 2005 Telcordia Technologies, Inc.