Reading and Research Questions in Intrusion Detection


Sponsor Wenke Lee wenke@cc.gatech.edu
Room 222, CCB
http://www.cc.gatech.edu/~wenke

Area Information Security


Problem

As the Internet plays an increasingly important role in our society, e.g., the infrastructure for E-Commerce and Digital Government, criminals and enemies have begun devising and launching sophisticated attacks motivated by financial, political, and even military objectives. It is imperative that we provide the best protection possible for our network infrastructures. Intrusion detection is a critical component of the defense-in-depth network security mechanisms. An intrusion detection system (IDS) collects and monitors operating system and network activity data, and analyzes the information to determine whether there is an attack occurring.

The purpose of this project is to explore the history of research in intrusion detection and to uncover what research challenges remain. Interested students should contact Wenke Lee and discuss what would be an appropriate list of readings and objectives.

Deliverables

Students should expect to do a literature search and read a good sample of research papers (at least 10). Students need to write a 10-20 pages summary report.

Evaluation

Evaluation is based on the quality of your deliverable.