@inproceedings{ kim1999human, author = "J. Kim and P. Bentley", title = "The Human Immune System and Network Intrusion Detection", booktitle = "7th European Congress on Intelligent Techniques and Soft Computing (EUFIT '99), Aachen, Germany, September 13-19", year = "1999", url = "citeseer.ist.psu.edu/kim99human.html" } @inproceedings{reis2002hybrid, title = {{A Hybrid IDS Architecture Based on the Immune System}}, author = "Marcelo Reis and Fabricio Paula and Diego Fernandes and Paulo Geus", booktitle = "XXX", year = "2002" } @inproceedings{forrest1994virus, title = {{Self-nonself discrimination in a computer}}, author = "S. Forrest and A.S. Perelson and L. Allen and R. Cherukuri", booktitle = "Proceedings of the 1994 IEEE Symposium on Research in Security and Privacy", publisher = "IEEE Computer Society Press", pages = {202-212}, year = "1994" } @article{forrest1997cacm, author = {Stephanie Forrest and Steven A. Hofmeyr and Anil Somayaji}, title = {{Computer Immunology}}, year = 1997, volume = 40, number = 10, pages = {88-96}, journal = {Communications of the ACM}, publisher = {ACM} } @article{hofmeyrforrest, title = {{Architecture for an Artificial Immune System}}, author = "S. Hofmeyr and S. Forrest", journal = "Evolutionary Computation Journal", volume = 8, number = 4, pages = {443-473}, year = 2000 } @inproceedings{forrest1997nspw, title = {{Principles of a Computer Immune System}}, author = "A. Somayaji and S. Hofmeyer and S. Forrest", booktitle = "Proceedings of the New Security Paradigms Workshop (NPSW)", pages = {75-82}, year = 1998 } @inproceedings{forrest1997hotos, author = "S. Forrest and A. Somayaji and D. Ackley", title = {{Building Diverse Computer Systems}}, booktitle = "Proceedings of the Sixth Workshop on Hot Topics in Operating Systems", pages = {67-72}, year = "1997" } @inproceedings{forrest2000syscalldelays, title = {{Automated Response Using System-Call Delays}}, author = "A. Somayaji and S. Forrest", booktitle = "Proceedings of the 9th USENIX Security Symposium", month = "August", year = 2000 } @thesis{somayaji2002thesis, title = {{Operating System Stability and Security through Process Homeostasis}}, author = "Anil B. Somayaji", publisher = "University of New Mexico", month = "July", year = "2002" } @inproceedings{kiriansky2002shepherding, author = "V. Kiriansky and D. Bruening and S. Amarasinghe", title = {{Secure Execution Via Program Shepherding}}, booktitle = "Proceedings of the 11th USENIX Security Symposium", month = "August", year = "2002" } @inproceedings{moorecontaining, title = {{Internet Quarantine: Requirements for Containing Self-Propagating Code}}, author = "Moore et al.", booktitle = "XXX", year = "2003" } @inproceedings{shieldSigcomm04, author = "Helen J. Wang and Chuanxiong Guo and Daniel R. Simon and Alf Zugenmaier", title = {{Shield: Vulnerability-Driven Network Filters for Preventing Known Vulnerability Exploits}}, booktitle = "Proceedings of the ACM SIGCOMM", month = "August", year = "2004" } @inproceedings{barrantes2003randomized, author = {E. G. Barrantes and D. H. Ackley and S. Forrest and T. S. Palmer and D. Stefanovic and D. D. Zovi}, year = 2003, month = {October}, booktitle = {Proceedings of the 10th ACM Conference on Computer and Communications Security (CCS)}, title = {{Randomized Instruction Set Emulation to Disrupt Binary Code Injection Attacks}}, pages = {281--289} } @inproceedings{gaurav2003isr, author = {Gaurav S. Kc and Angelos D. Keromytis and Vassilis Prevelakis}, title = {{Countering Code-Injection Attacks With Instruction-Set Randomization}}, year = 2003, month = {October}, pages = {272--280}, booktitle = {Proceedings of the ACM Computer and Communications Security (CCS) Conference} } @inproceedings{saber, title = {{A Holistic Approach to Service Survivability}}, author = "Angelos D. Keromytis and Janak Parekh and Philip N. Gross and Gail Kaiser and Vishal Misra and Jason Nieh and Dan Rubenstein and Sal Stolfo", booktitle = "Proceedings of the 1st ACM Workshop on Survivable and Self-Regenerative Systems (SSRS)", pages = {11-22}, month = "October", year = "2003" } @inproceedings{wormvaccine, author = {S. Sidiroglou and A. D. Keromytis}, title = {{A Network Worm Vaccine Architecture}}, year = 2003, month = {June}, booktitle = {Proceedings of the IEEE Workshop on Enterprise Technologies: Infrastructure for Collaborative Enterprises (WETICE), Workshop on Enterprise Security}, pages = {220--225} } @inproceedings{scandariato2004worm, author = "Riccardo Scandariato and John C. Knight", title = {{An Automated Defense System to Counter Internet Worms}}, booktitle = "DSN", year = "2004" } @inproceedings{boyd2004sqlrand, author = "Stephen Boyd and Angelos Keromytis", title = {{SQLrand: Preventing SQL Injection Attacks}}, booktitle = "Proceedings of the 2nd Applied Cryptography and Network Security (ACNS) Conference", month = "June", year = "2004" } @inproceedings{rinard2004dynamicmemerr, title = {{A Dynamic Technique for Eliminating Buffer Overflow Vulnerabilities (and Other Memory Errors)}}, author = "Martin Rinard and Cristian Cadar and Daniel Dumitran and Daniel Roy and Tudor Leu", booktitle = "Proceedings 20th Annual Computer Security Applications Conference (ACSAC) 2004", month = "December", year = "2004" } @inproceedings{rinard2004osdi, title = "Enhancing Server Availability and Security Through Failure-Oblivious Computing", author = "M. Rinard and C. Cadar and D. Dumitran and D. Roy and T. Leu and W Beebee, Jr.", booktitle = "Proceedings 6th Symposium on Operating Systems Design and Implementation (OSDI)", month = "December", year = "2004" } @inproceedings{crashonly, title = "Crash-Only Software", author = "George Candea and Armando Fox", booktitle = "Proceedings of the 9th Workshop on Hot Topics in Operating Systems", month = "May", year = "2003" } @inproceedings{demsky2003oopsla, author = "Brian Demsky and Martin C. Rinard", title = {{Automatic Detection and Repair of Errors in Data Structures}}, booktitle = "Proceedings of the 18th Annual ACM SIGPLAN Conference on Object Oriented Programming, Systems, Languages, and Applications", month = "October", year = "2003" } @inproceedings{demsky2003sms, author = "Brian Demsky and Martin C. Rinard", title = {{Automatic Data Structure Repair for Self-Healing Systems}}, booktitle = "Proceedings of the 1st Workshop on Algorithms and Architectures for Self-Managing Systems", month = "June", year = "2003" } @inproceedings{kewang2004payl, author = "Ke Wang and Salvatore J. Stolfo", title = {{Anomalous Payload-based Network Intrusion Detection}}, booktitle = "Proceedings of the Recent Advances in Intrusion Detection (RAID) Conference", month = "September", year = "2004" } @inproceedings{pal2000tolerant, title = {{Intrusion Tolerant Systems}}, author = "Partha Pal and Franklin Webber and Richard Schantz and Joseph P. Loyall", booktitle = "Proceedings of the ISW", year = "2000" } @inproceedings{pal2001defense, title = {{Survival by Defense-Enabling}}, author = "Partha Pal and Franklin Webber and Richard Schantz", booktitle = "Proceedings of the New Security Paradigms Workshop (NSPW)", pages = "71-78", month = "September", year = "2001" } @techreport{lapadula1998, title = {{Intrusion Reaction: Recommendations for Obtaining Reaction Capabilities}}, author = "Leonard J. LaPadula", publisher = "The MITRE Corporation", month = "September", year = "1998" } @inproceedings{bruschi2001nspw, title = {{AngeL: a tool to disarm computer systems}}, author = "Danilo Bruschi and Emilia Rosti", booktitle = "Proceedings of the New Security Paradigms Workshop (NSPW)", pages = "63-69", month = "September", year = "2001" } @inproceedings{naldurg2003dynamic, title = {{Dynamic Access Control: Preserving Safety and Trust for Network Defense Operations}}, author = "Prasad Naldurg and Roy H. Campbell", booktitle = "Proceedings of the 8th ACM Symposium on Access Control Models and Technologies (SACMAT) 2003", month = "June", year = "2003" } @inproceedings{reynolds2003hacqit, title = {{On-Line Intrusion Detection and Attack Prevention Using Diversity, Genrate-and-Test, and Generalization}}, author = "James C. Reynolds and James Just and Larry Clough and Ryan Maglich", booktitle = "Proceedings of the 36th Hawaii International Conference on System Sciences (HICSS) 2003", year = "2003" } @inproceedings{ioannidis2002pushback, author = "John Ioannidis and Steven M. Bellovin", title = "Implementing Pushback: Router-Based Defense Against {DDoS} Attacks", booktitle = "Proceedings of Network and Distributed System Security (NDSS) Symposium", publisher = "The Internet Society", address = " 1775 Wiehle Ave., Suite 102, Reston, VA 20190", month = "February", year = 2002, url = "citeseer.ist.psu.edu/ioannidis02implementing.html" } @techreport{strunk2002storage, title = {{Intrusion Detection, Diagnosis, and Recovery with Self-Securing Storage}}, author = "John D. Strunk and Garth R. Goodson and Adam G. Pennington and Craig Soules and Gregory Ganger", howpublished = "CMU Computer Science Technical Report CMU-CS-02-140", month = "May", year = "2002" } @inproceedings{provos2002systrace, title = {{Improving Host Security with System Call Policies}}, author = "Niels Provos", booktitle = "Proceedings of the 12th USENIX Security Symposium", pages = {207-225}, month = "August", year = "2003" } @inproceedings{fraser99hardening, title = {{Hardening COTS Software with Generic Software Wrappers}}, author = "Timothy Fraser and Lee Badger and Mark Feldman", booktitle = "Proceedings of the 1999 IEEE Symposium on Security and Privacy", year = "1999" } @inproceedings{libsafe-usenix00, title = {{Transparent Run-Time Defense Against Stack Smashing Attacks}}, author = "Arash Baratloo and Navjot Singh and Timothy Tsai", booktitle = "Proceedings of the USENIX General Technical Conference", year = 2000 } @article{kreidl2002feedback, title = {{Feedback Control Applied to Survivability: A Host-Based Autonomic Defense System}}, author = "O. Patrick Kreidl and Tiffany M. Frazier", journal = "IEEE Transactions on Reliability", volume = "", number = "", year = "2002" } @inproceedings{reynolds2003repair, title = {{Continual Repair for Windows Using the Event Log}}, author = "James C. Reynolds and Lawrence A. Clough", booktitle = "Proceedings of the 1st ACM Workshop on Survivable and Self-Regenerative Systems (SSRS)", pages = {99-104}, month = "October", year = "2003" } @inproceedings{porras2004hybrid, title = {{A Hybrid Quarantine Defense}}, author = "Phillip Porras and L. Briesemeister and K. Skinner and K. Levitt and J. Rowe and Y. A. Ting", booktitle = "Proceedings of the ACM CCS Workshop on Rapid Malcode (WORM) 2004", month = "October", year = "2004" } @inproceedings{icon03-worm, title = {{A Cooperative Immunization System for an Untrusting Internet}}, author = "Kostas Anagnostakis and Michael B. Greenwald and Sotiris Ioannidis and Angelos D. Keromytis and Dekai Li. ", booktitle ="Proceedings of the 11th IEEE International Conference on Networks (ICON)", pages = {403-408}, month = "October", year = "2003" } @inproceedings{prasad2003binary, title = {{A Binary Rewriting Defense Against Stack-based Buffer Overflow Attacks}}, author = "M. Prasad and T. Chiueh", booktitle = "Proceedings of the USENIX Annual Technical Conference", month = "June", year = "2003" } @inproceedings{wolf2000bend, title = {{Bend, Don't Break: Using Reconfiguration to Achieve Survivability}}, author = "A. Wolf and D. Heimbigner and A. Carzaniga and J. Knight and P. Devenbu and M. Gertz", booktitle = "Proceedings of the 3rd Information Survivability Workshop", pages = {187-190}, month = "October", year = "2000" } @inproceedings{atighetchi2003apod, title = {{Adaptive Use of Network-Centric Mechanisms in Cyber-Defense}}, authors = "Michael Atighetchi and Partha Pal and Franklin Webber and Christopher Jones", booktitle = "Proceedings of the 2nd IEEE International Symposium on Network Computing and Applications", month = "April", year = "2003" } @article{ghosh1999cacm, title = {{Innoculating Software for Survivability}}, author = "Anup K. Ghosh and Jeffery M. Voas", journal = "Communications of the ACM", volume = "42", number = "7", year = "1999" } @inproceedings{bhatkar2003ao, title = {{Address Obfuscation: An Efficient Approach to Combat a Broad Range of Memory Error Exploits}}, author = "S. Bhatkar and D.C. DuVarney and R. Sekar", booktitle = "Proceedings of the 12th USENIX Security Symposium", pages = {105-120}, month = "August", year = "2003" } @inproceedings{shacham2004ccs, title = {{On the Effectiveness of Address-Space Randomization}}, author = "H. Shacham and M. Page and B. Pfaff and E.J. Goh and N. Modadugu and D. Boneh", booktitle = "Proceedings of the 11th ACM Conference on Computer and Communications Security (CCS)", pages = {298-307}, month = "October", year = "2004" } @inproceedings{odonnell2004coloring, title = {{On Achieving Software Diversity for Improved Network Security Using Distributed Coloring Algoritms}}, author = "Adam J. O'Donnell and Harish Sethu", booktitle = "Proceedings of the 11th ACM Conference on Computer and Communications Security (CCS)", pages = {121-131}, month = "October", year = "2004" } @inproceedings{bernaschi2000syscall, title = {{Operating System Enhancements to Prevent the Misuse of System Calls}}, author = "M. Bernaschi and L. Mancini and E. Gabrielli", booktitle = "Proceedings of the 7th ACM Conference on Computer and Communications Security (CCS)", pages = {174}, year = "2000" } @inproceedings{ko2000wrappers, title = {{Detecting and Countering System Intrusions Using Software Wrappers}}, author = "Calvin Ko and Timothy Fraser and Lee Badger and Douglas Kilpatrick", booktitle = "Proceedings of the 9th USENIX Security Symposium", year = "2000" } @inproceedings{sekar1999syscall, title = {{Synthesizing Fast Intrusion Prevention/Detection Systems from High-Level Specifications}}, author = "R. Sekar and P. Uppuluri", booktitle = "Proceedings of the 8th USENIX Security Symposium", year = "1999" } @inproceedings{barak1999toolkit, title = {{The Proactive Security Toolkit and Applications}}, author = " Boaz Barak and Amir Herzberg and Dalit Naor and Eldad Shai", booktitle = "Proceedings of the 6th ACM Conference on Computer and Communications Security (CCS)", month = "November", year = "1999" } @inproceedings{abadi2003ac, title = {{Access Control Based on Execution History}}, author = "Martin Abadi and Cedric Fournet", booktitle = "Proceedings of the 2003 Symposium on Network and Distributed Systems Security (NDSS)", year = "2003" } @inproceedings{overill1998question, title = {{How Re(Pro)active Should an IDS Be?}}, author = "Richard E. Overill", booktitle = "Proceedings of the 1st International Workshop on Recent Advances in Intrusion Detection (RAID)", month = "September", year = "1998" } @inproceedings{nidar, title = {{NIDAR: The Design and Implementation of an Intrusion Detection System}}, author = "Tan Yong Tai and Tan Woon Kiong and Ong Tiang Hwee and C. Ting", booktitle = "Proceedings of the 1st International Workshop on Recent Advances in Intrusion Detection (RAID)", year = "1998" } @inproceedings{queiroz1999micael, title = {{Micael: An Autonomous Mobile Agent System to Protect New Generation Networked Applications}}, author = "Jose Duarte de Queiroz et al.", booktitle = "Proceedings of the 2nd International Workshop on Recent Advances in Intrusion Detection (RAID)", year = "1999" } @inproceedings{rowe1999idip, title = {{Intrusion Detection and Isolation Protocol: Automated Response to Attacks}}, author = "Jeff Rowe and D. Schnackenberg and D. Darby and K. Levitt and C. Wee and D. Klotz and J. Schatz", booktitle = "Proceedings of the 2nd International Workshop on Recent Advances in Intrusion Detection (RAID)", year = "1999" } @inproceedings{balepin2003raid, title = {{Using Specification-Based Intrusion Detection for Automated Response}}, author = "Ivan Balepin and Sergei Maltsev and Jeff Rowe and Karl Levitt", booktitle = "Proceedings of the 6th International Workshop on Recent Advances in Intrusion Detection (RAID)", month = "September", year = "2003" } @inproceedings{welch1999nspw, title = {{Strike Back: Offensive Actions in Information Warfare}}, author = "Welch", booktitle = "Proceedings of the New Security Paradigms Workshop (NSPW)", year = "1999" } @inproceedings{nojiri2003coop, title = {{Cooperative Response Strategies for Large Scale Attack Mitigation}}, author = "D. Nojiri and J. Rowe and K. Levitt", booktitle = "Proceedings of The Third DARPA Information Survivability Conference and Exposition (DISCEX III), ", month = "April", year = "2003" } @article{wang2001tracing, title = {{Tracing Based Active Intrusion Response}}, author = "X.Wang and D. Reeves and S.F. Wu", journal = "Journal of Information Warfare", volume = "1", issue = "1", month = "September", pages = {50-61}, year = "2001" } @article{yuill2000, title = {{Intrusion-detection for incident-response, using a military battlefield-intelligence process}}, author = "J. Yuill and S.F. Wu and J. Settle and F. Gong and R. Forno and M. Huang and J. Asbery", journal = "Computer Networks", volume = "34", number = "4", pages = {671-697}, year = "2000" } @misc{ ragsdale00adaptation, author = "D. Ragsdale and C. Carver and J. Humphries and U. Pooch", title = "Adaptation techniques for intrusion detection and intrusion response system", text = "D. Ragsdale, C.A. Carver, J. Humphries, and U. Pooch. Adaptation techniques for intrusion detection and intrusion response system. Proceedings of the IEEE International Conference on Systems, Man, and Cybernetics at Nashville, Tennessee,pages 2344--2349, October 8-11 2000.", year = "2000", url = "citeseer.ist.psu.edu/ragsdale00adaptation.html" }