Explaining and Recovering from Computer Intrusion: Status 97




Douglas B. Moran
Artificial Intelligence Center
SRI International
333 Ravenswood Avenue
Menlo Park CA 94025

2/26/97

Overview


Initial Focus: Rootkit


Rootkit: Background


Multiple Entry Points


Multiple Entry Points:
Bi-directional Paths


Alternate Sources of Evidence


Alternate Lines of Attack


Incomplete Evidence


Implementation Approach


System Engineering Issues


System Engineering Issues


Conclusion


Issues


Procedural Reasoning System


Diagnosis


Explanation


Reporting


Recovery


Distributed


Intrusion Scenarios


Security Policy:
Propagating Changes


Many Sites
Many Security Policies


Approach


Back to Security Project Home Page
Back to AI Center Home Page
Back to SRI International Home Page

Pauline M. Berry berry@ai.sri.com