A Revised Taxonomy of Data Collection Mechanisms with a Focus on Intrusion Detection
Paper in proceeding, 2008

Surprisingly few data collection mechanisms have been used for intrusion detection, and most systems rely on network and system call data as input to the detection engine. Even though the quality of log data is vital to the detection process and heavily dependent on the collection mechanism, no extensive survey or taxonomy has been conducted within the detection field. In this paper, we propose a revised taxonomy which provides a unified terminology and a framework in which data collection mechanisms can be systematically inspected, evaluated, and compared. Since the taxonomy is derived from existing mechanisms, it also provides a useful overview of different types of mechanisms. The paper also suggests areas within data collection where additional work is required.

Data collection

intrusion detection

taxonomy

Author

Ulf Larson

Chalmers, Computer Science and Engineering (Chalmers), Computer Engineering (Chalmers)

Stefan Lindskog

Chalmers

Erland Jonsson

Chalmers, Computer Science and Engineering (Chalmers), Computer Engineering (Chalmers)

Proceedings of the Third IEEE International Conference on Availability, Reliability and Security (ARES 2008)

624-629
978-076953102-1 (ISBN)

Subject Categories

Computer Engineering

DOI

10.1109/ARES.2008.38

ISBN

978-076953102-1

More information

Latest update

9/10/2018