CS 97 Senior Conference: Intrusion Detection
TR 2:40-3:55pm, SCI 246
Fall 2005
Swarthmore College

Professor: Benjamin Kuperman
email: kuperman AT cs swarthmore edu
Please include "CS97" in the subject.
AIM: ProfKuperman
Office: SCI 253
Phone: 328-8665
Office Hours: Mon 2-3pm, Wed 9:30-11:00am

Quick link to http://edventure.brynmawr.edu/


Announcements


Contents


Course Description


Text and Useful Links

There is no text for this course, though I will put a number of books from my personal collection on reserve in the library.

The following websites are good sources for information on papers in this course and similar areas:

General Computer Security Paper Collections

Security Sites

If you find other useful sites, let me know and I'll add them.


Grading

Grades will be calculated based on the following distribution:

Reading Responses/Critiques

Paper Presentations


Homework and Course Policy


Schedule

(Subject to change)
WEEK DAY Note READING HW
1 Aug 30   Administrivia Background
Sep 01   Background of IDS
  1. Computer Security Threat Monitoring and Surveillance, James P. Anderson, 1980.
  2. An Intrusion Detection Model, Dorothy E. Denning, 1986.
2 Sep 06   Taxonomy (Ben)
  1. AINT Misbehaving: A Taxonomy of Anti-Intrusion Techniques, Lawrence R. Halme and R. Kenneth Bauer, 2000. (local copy)
  2. Towards a Taxonomy of intrusion-detction systems, Herve Debar, Marc Dacier, and Andreas Wespi, 1999.
Sep 08   Pattern matching (Ken)
  1. A pattern matching model for misuse intrusion detection, Sandeep Kumar and Gene Spafford, 1994.
  2. A secure environment for untrusted helper applications, Goldberg et al, 1996. (Janus)
3 Sep 13   Honeynets (Heather)
  1. An evening with Berferd, Bill Cheswick
  2. Honeynets, Honeynet Arms Race, KYE Profile: Credit Card Fraud
Sep 15   Network intrusion detection (Javier)
  1. Network Intrusion Detection, Biswanath Mukherjee, Todd Heberlein, Karl N. Levitt, 1994.
  2. Bro: A system for detecting network intruders in real time, Vern Paxon 1999
4 Sep 20   Insertion and Evasion (Connie)
  1. Insertion, Evastion, and Denial of Service: Eluding Network Intrusion Detection, Thomas H. Ptacek and Timothy N. Newsham, 1998.
Initial Project Proposal
Sep 22   Happy-fun Honeypot day
5 Sep 27   Computer Immunology (Ethan?) (Javier)
  1. A Sense of Self for Unix Processes, Stephanie Forrest et al, 1996.
  2. Immune System Approaches to Intrusion Detection - A Review, Aickelin et al.
Literature Search/Review
Sep 29   DARPA IDS Shootout (Ben)
  1. Testing Intrusion Detection Systems, John McHugh, 2000.
6 Oct 04   Machine Learning(Alan)
  1. Lane, Brodley
  2. Lee, Stolfo
Oct 06   Base Rate Fallacy
  Oct 11 October Break (Oct 8 - 17)
Oct 13
7 Oct 18   Proposal Presentations (10 min) Revised Proposal
Oct 20   Paper presentation planning and instructions on critiquing
8 Oct 25   Anonymous Networks (Dan)
  1. Onion Routing
  2. Crowds CACM Article (Journal Article)
Work on Project
Oct 27   Honeypot Forensics (Connie)
  1. Honeypot Forensics
9 Nov 01   Alert Correlation (Javier)
Nov 03   Evolving 3D Morphology (Ethan)
10 Nov 08   Network Traceback (Ken)
Nov 10   Neural Networks (Ben)
11 Nov 15   Security Tools (Alan) Rough Draft
Nov 17   Warhol Worms (Grant)
12 Nov 22   Worm Taxonomy (Heather) Presentation
Nov 24 Thanksgiving Break (Nov 24 - 28)
13 Nov 29   Student Project Presentation 1, 2, 3
Dec 01   Student Project Presentation 4, 5, 6
14 Dec 06   Student Project Presentation 7 + overflow
  Dec 13 Final Paper Due

Papers


Last Modified: Thu 20 Oct 2005 02:23:08 PM EDT - Benjamin A. KupermanVI Powered