Intrusion detection and virology: an analysis of differences, similarities and complementariness
Generate an AI Snapshot to get a quick, structured summary of this paper.
A concise AI-generated summary of the paper will appear here once you click Generate AI Snapshot.
TL;DR
This analysis of the differences, similarities and complementariness which exist between two major domains of nowadays information security: intrusion detection on one hand, virology and anti-viruses technologies on the other hand suggests that alert correlation is one way to make the two fields cooperate.
Abstract
In this paper, we analyze the differences, similarities and complementariness which exist between two major domains of nowadays information security: intrusion detection on one hand, virology and anti-viruses technologies on the other hand. This analysis is built from two points of view. First, we compare, through the definitions that have been proposed by researchers of the two communities, the goals that are actually pursued in each domain. Then, we compare the techniques that have been developed to reach these goals. In the conclusion, we summarize our analysis and suggest that alert correlation is one way to make the two fields cooperate.
