{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T03:30:17Z","timestamp":1761708617692,"version":"3.41.0"},"reference-count":47,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2010,12,1]],"date-time":"2010-12-01T00:00:00Z","timestamp":1291161600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100006602","name":"Air Force Research Laboratory","doi-asserted-by":"publisher","award":["F49620-01-1-0433"],"award-info":[{"award-number":["F49620-01-1-0433"]}],"id":[{"id":"10.13039\/100006602","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["DAAD19-02-1-0389"],"award-info":[{"award-number":["DAAD19-02-1-0389"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2010,12]]},"abstract":"<jats:p>Storage-based intrusion detection consists of storage systems watching for and identifying data access patterns characteristic of system intrusions. Storage systems can spot several common intruder actions, such as adding backdoors, inserting Trojan horses, and tampering with audit logs. For example, examination of 18 real intrusion tools reveals that most (15) can be detected based on their changes to stored files. Further, an Intrusion Detection System (IDS) embedded in a storage device continues to operate even after client operating systems are compromised. We describe and evaluate a prototype storage IDS, built into a disk emulator, to demonstrate both feasibility and efficiency of storage-based intrusion detection. In particular, both the performance overhead (&lt;\u20091%) and memory required (1.62MB for 13995 rules) are minimal.<\/jats:p>","DOI":"10.1145\/1880022.1880024","type":"journal-article","created":{"date-parts":[[2010,12,29]],"date-time":"2010-12-29T14:32:48Z","timestamp":1293633168000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Storage-Based Intrusion Detection"],"prefix":"10.1145","volume":"13","author":[{"given":"Adam G.","family":"Pennington","sequence":"first","affiliation":[{"name":"Carnegie Mellon University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John Linwood","family":"Griffin","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John S.","family":"Bucy","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John D.","family":"Strunk","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gregory R.","family":"Ganger","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2010,12]]},"reference":[{"volume-title":"Department of Computer Engineering","author":"Axelsson S.","key":"e_1_2_1_1_1","unstructured":"Axelsson , S. 1998. Research in intrusion-detection systems: A survey. Tech. rep. 98--17 , Department of Computer Engineering , Chalmers University of Technology . Axelsson, S. 1998. Research in intrusion-detection systems: A survey. Tech. rep. 98--17, Department of Computer Engineering, Chalmers University of Technology."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSST.2005.33"},{"key":"e_1_2_1_3_1","first-page":"131","article-title":"Checking for race conditions in file accesses","volume":"9","author":"Bishop M.","year":"1996","unstructured":"Bishop , M. and Dilger , M. 1996 . Checking for race conditions in file accesses . Comput. Syst. 9 , 2, 131 -- 152 . Bishop, M. and Dilger, M. 1996. Checking for race conditions in file accesses. Comput. Syst. 9, 2, 131--152.","journal-title":"Comput. Syst."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455821"},{"volume-title":"Proceedings of the 1st Dutch International Symposium on Linux.","author":"Card R.","key":"e_1_2_1_5_1","unstructured":"Card , R. , Ts\u2019o , T. , and Tweedie , S . 1994. Design and implementation of the second extended file system . In Proceedings of the 1st Dutch International Symposium on Linux. Card, R., Ts\u2019o, T., and Tweedie, S. 1994. Design and implementation of the second extended file system. In Proceedings of the 1st Dutch International Symposium on Linux."},{"volume-title":"Proceedings of the Symposium on Operating Systems Design and Implementation. USENIX Association, 273--287","author":"Castro M.","key":"e_1_2_1_6_1","unstructured":"Castro , M. and Liskov , B . 2000. Proactive recovery in a byzantine-fault-tolerant system . In Proceedings of the Symposium on Operating Systems Design and Implementation. USENIX Association, 273--287 . Castro, M. and Liskov, B. 2000. Proactive recovery in a byzantine-fault-tolerant system. In Proceedings of the Symposium on Operating Systems Design and Implementation. USENIX Association, 273--287."},{"volume-title":"Proceedings of the Conference on Hot Topics in Operating Systems. IEEE Computer Society, 133--138","author":"Chen P. M.","key":"e_1_2_1_7_1","unstructured":"Chen , P. M. and Noble , B. D . 2001. When virtual is better than real . In Proceedings of the Conference on Hot Topics in Operating Systems. IEEE Computer Society, 133--138 . Chen, P. M. and Noble, B. D. 2001. When virtual is better than real. In Proceedings of the Conference on Hot Topics in Operating Systems. IEEE Computer Society, 133--138."},{"key":"e_1_2_1_8_1","unstructured":"Cheswick B. and Bellovin S. 1994. Firewalls and Internet Security: Repelling the Wily Hacker. Addison-Wesley Reading MA. Cheswick B. and Bellovin S. 1994. Firewalls and Internet Security: Repelling the Wily Hacker . Addison-Wesley Reading MA."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1987.232894"},{"volume-title":"Information Warfare and Security","author":"Denning D. E.","key":"e_1_2_1_10_1","unstructured":"Denning , D. E. 1999. Information Warfare and Security . Addison-Wesley , Reading, MA . Denning, D. E. 1999. Information Warfare and Security. Addison-Wesley, Reading, MA."},{"key":"e_1_2_1_11_1","unstructured":"Farmer D. 2000. What are MACtimes? Dr. Dobb\u2019s J. 25 10 68--74. Farmer D. 2000. What are MACtimes? Dr. Dobb\u2019s J. 25 10 68--74."},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 120--128","author":"Forrest S.","key":"e_1_2_1_12_1","unstructured":"Forrest , S. , Hofmeyr , S. A. , Somayaji , A. , and Longstaff , T. A . 1996. A sense of self for UNIX processes . In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 120--128 . Forrest, S., Hofmeyr, S. A., Somayaji, A., and Longstaff, T. A. 1996. A sense of self for UNIX processes. In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 120--128."},{"volume-title":"Proceedings of the Conference on Hot Topics in Operating Systems. IEEE, 100--105","author":"Ganger G. R.","key":"e_1_2_1_13_1","unstructured":"Ganger , G. R. and Nagle , D. F . 2001. Better security via smarter devices . In Proceedings of the Conference on Hot Topics in Operating Systems. IEEE, 100--105 . Ganger, G. R. and Nagle, D. F. 2001. Better security via smarter devices. In Proceedings of the Conference on Hot Topics in Operating Systems. IEEE, 100--105."},{"key":"e_1_2_1_14_1","unstructured":"Ganger G. R. Economou G. and Bielski S. M. 2003. Finding and containing enemies within the walls with self-securing network interfaces. Tech. rep. CMU-CS-03-109 Carnegie Mellon University. Ganger G. R. Economou G. and Bielski S. M. 2003. Finding and containing enemies within the walls with self-securing network interfaces. Tech. rep. CMU-CS-03-109 Carnegie Mellon University."},{"volume-title":"Proceedings of the Annual Network and Distributed System Security Symposium (NDSS\u201903)","author":"Garfinkel T.","key":"e_1_2_1_15_1","unstructured":"Garfinkel , T. and Rosenblum , M . 2003. A virtual machine introspection based architecture for intrusion detection . In Proceedings of the Annual Network and Distributed System Security Symposium (NDSS\u201903) . The Internet Society. Garfinkel, T. and Rosenblum, M. 2003. A virtual machine introspection based architecture for intrusion detection. In Proceedings of the Annual Network and Distributed System Security Symposium (NDSS\u201903). The Internet Society."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/384265.291029"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/35037.35059"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.15325\/ATTTJ.1996.6771126"},{"key":"e_1_2_1_21_1","volume-title":"Postmark: A new file system benchmark. Tech. rep. TR3022, Network Appliance.","author":"Katcher J.","year":"1997","unstructured":"Katcher , J. 1997 . Postmark: A new file system benchmark. Tech. rep. TR3022, Network Appliance. Katcher, J. 1997. Postmark: A new file system benchmark. Tech. rep. TR3022, Network Appliance."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/191177.191183"},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 175--187","author":"Ko C.","key":"e_1_2_1_23_1","unstructured":"Ko , C. , Ruschitzka , M. , and Levitt , K . 1997. Execution monitoring of security-critical pro- grams in distributed systems: A specification-based approach . In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 175--187 . Ko, C., Ruschitzka, M., and Levitt, K. 1997. Execution monitoring of security-critical pro- grams in distributed systems: A specification-based approach. In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 175--187."},{"volume-title":"Proceedings of the USENIX Annual Technical Conference. USENIX Association, 95--106","author":"Kumar P.","key":"e_1_2_1_24_1","unstructured":"Kumar , P. and Satyanarayanan , M . 1995. Flexible and safe resolution of file conflicts . In Proceedings of the USENIX Annual Technical Conference. USENIX Association, 95--106 . Kumar, P. and Satyanarayanan, M. 1995. Flexible and safe resolution of file conflicts. In Proceedings of the USENIX Annual Technical Conference. USENIX Association, 95--106."},{"key":"e_1_2_1_25_1","unstructured":"Lemos R. 2002. Putting fun back into hacking. http:\/\/zdnet.com\/100-1105-948404.html. Lemos R. 2002. Putting fun back into hacking. http:\/\/zdnet.com\/100-1105-948404.html."},{"key":"e_1_2_1_26_1","volume-title":"Proceedings of the IFIP Working Conference on Database Security. IFIP, 3--18","author":"Liu P.","year":"2000","unstructured":"Liu , P. , Jajodia , S. , and McCollum , C. D. 2000 . Intrusion confinement by isolation in infor- mation systems . In Proceedings of the IFIP Working Conference on Database Security. IFIP, 3--18 . Liu, P., Jajodia, S., and McCollum, C. D. 2000. Intrusion confinement by isolation in infor- mation systems. In Proceedings of the IFIP Working Conference on Database Security. IFIP, 3--18."},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 59--66","author":"Lunt T. F.","key":"e_1_2_1_27_1","unstructured":"Lunt , T. F. and Jagannathan , R . 1988. A prototype real-time intrusion-detection expert system . In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 59--66 . Lunt, T. F. and Jagannathan, R. 1988. A prototype real-time intrusion-detection expert system. In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, 59--66."},{"key":"e_1_2_1_28_1","unstructured":"NFR 2002. Nfr security. http:\/\/www.nfr.net\/.  NFR 2002. Nfr security. http:\/\/www.nfr.net\/."},{"key":"e_1_2_1_29_1","unstructured":"Packetstorm 2009. Packet storm security. http:\/\/www.packetstormsecurity.org\/. Packetstorm 2009. Packet storm security. http:\/\/www.packetstormsecurity.org\/."},{"volume-title":"Proceedings of the CoBaSSA -- Workshop on Code Based Software Security Assessments.","author":"Paul N.","key":"e_1_2_1_30_1","unstructured":"Paul , N. , Gurumurthi , S. , and Evans , D . 2005. Towards disk-level malware detection . In Proceedings of the CoBaSSA -- Workshop on Code Based Software Security Assessments. Paul, N., Gurumurthi, S., and Evans, D. 2005. Towards disk-level malware detection. In Proceedings of the CoBaSSA -- Workshop on Code Based Software Security Assessments."},{"key":"e_1_2_1_32_1","volume-title":"Proceedings of the USENIX Security Symposium. USENIX Association, 31--51","author":"Paxson V.","year":"1998","unstructured":"Paxson , V. 1998 . Bro: A system for detecting network intruders in real-time . In Proceedings of the USENIX Security Symposium. USENIX Association, 31--51 . Paxson, V. 1998. Bro: A system for detecting network intruders in real-time. In Proceedings of the USENIX Security Symposium. USENIX Association, 31--51."},{"volume-title":"Proceedings of the Computer Security Applications Conference (ACSAC\u201907)","author":"Payne B. D.","key":"e_1_2_1_33_1","unstructured":"Payne , B. D. , de A. Carbone , M. D. P. , and Lee , W . 2007. Secure and flexible monitoring of virtual machines . In Proceedings of the Computer Security Applications Conference (ACSAC\u201907) . IEEE, 385--397. Payne, B. D., de A. Carbone, M. D. P., and Lee, W. 2007. Secure and flexible monitoring of virtual machines. In Proceedings of the Computer Security Applications Conference (ACSAC\u201907). IEEE, 385--397."},{"volume-title":"Proceedings of the USENIX Security Symposium.","author":"Pennington A. G.","key":"e_1_2_1_34_1","unstructured":"Pennington , A. G. , Strunk , J. D. , Griffin , J. L. , Soules , C. A.N. , Goodson , G. R. , and Ganger , G. R . 2003. Storage-based intrusion detection: Watching storage activity for suspicious behavior . In Proceedings of the USENIX Security Symposium. Pennington, A. G., Strunk, J. D., Griffin, J. L., Soules, C. A.N., Goodson, G. R., and Ganger, G. R. 2003. Storage-based intrusion detection: Watching storage activity for suspicious behavior. In Proceedings of the USENIX Security Symposium."},{"volume-title":"Proceedings of the National Information Systems Security Conference. 353--365","author":"Porras P. A.","key":"e_1_2_1_35_1","unstructured":"Porras , P. A. and Neumann , P. G . 1997. EMERALD: Event monitoring enabling responses to anomalous live disturbances . In Proceedings of the National Information Systems Security Conference. 353--365 . Porras, P. A. and Neumann, P. G. 1997. EMERALD: Event monitoring enabling responses to anomalous live disturbances. In Proceedings of the National Information Systems Security Conference. 353--365."},{"key":"e_1_2_1_36_1","unstructured":"Purczynski W. 2002. Gnu fileutils -- Recursive directory removal race condition. http:\/\/www.mail-archive.com\/bug-fileutils@gnu.org\/msg01537.html. Purczynski W. 2002. Gnu fileutils -- Recursive directory removal race condition. http:\/\/www.mail-archive.com\/bug-fileutils@gnu.org\/msg01537.html."},{"key":"e_1_2_1_37_1","volume-title":"R. J","author":"Samar V.","year":"1995","unstructured":"Samar , V. and Schemers III , R. J . 1995 . Unified login with pluggable authentication modules (PAM). Tech. rep., Open Software Foundation RFC 86.0, Open Software Foundation . Samar, V. and Schemers III, R. J. 1995. Unified login with pluggable authentication modules (PAM). Tech. rep., Open Software Foundation RFC 86.0, Open Software Foundation."},{"key":"e_1_2_1_38_1","volume-title":"Hacking Exposed: Network Security Secrets and Solutions. Osborne\/McGraw-Hill.","author":"Scambray J.","year":"2001","unstructured":"Scambray , J. , McClure , S. , and Kurtz , G . 2001 . Hacking Exposed: Network Security Secrets and Solutions. Osborne\/McGraw-Hill. Scambray, J., McClure, S., and Kurtz, G. 2001. Hacking Exposed: Network Security Secrets and Solutions. Osborne\/McGraw-Hill."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/317087.317089"},{"volume-title":"Proceedings of the Conference on File and Storage Technologies. USENIX Association, 73--88","author":"Sivathanu M.","key":"e_1_2_1_40_1","unstructured":"Sivathanu , M. , Prabhakaran , V. , Popovici , F. I. , Denehy , T. E. , Arpaci-Dusseau , A. C. , and Arpaci-Dusseau , R. H . 2003. Semantically smart disk systems . In Proceedings of the Conference on File and Storage Technologies. USENIX Association, 73--88 . Sivathanu, M., Prabhakaran, V., Popovici, F. I., Denehy, T. E., Arpaci-Dusseau, A. C., and Arpaci-Dusseau, R. H. 2003. Semantically smart disk systems. In Proceedings of the Conference on File and Storage Technologies. USENIX Association, 73--88."},{"key":"e_1_2_1_41_1","unstructured":"Strom R. 2008. Emc Celerra family technical review. http:\/\/www.emc.com\/pdf\/partnersalliances\/einfo\/McAfee_netshield.pdf. Strom R. 2008. Emc Celerra family technical review. http:\/\/www.emc.com\/pdf\/partnersalliances\/einfo\/McAfee_netshield.pdf."},{"volume-title":"Proceedings of the Symposium on Operating Systems Design and Implementation. USENIX Association, 165--180","author":"Strunk J. D.","key":"e_1_2_1_42_1","unstructured":"Strunk , J. D. , Goodson , G. R. , Scheinholtz , M. L. , Soules , C. A. N. , and Ganger , G. R . 2000. Self-securing storage: Protecting data in compromised systems . In Proceedings of the Symposium on Operating Systems Design and Implementation. USENIX Association, 165--180 . Strunk, J. D., Goodson, G. R., Scheinholtz, M. L., Soules, C. A. N., and Ganger, G. R. 2000. Self-securing storage: Protecting data in compromised systems. In Proceedings of the Symposium on Operating Systems Design and Implementation. USENIX Association, 165--180."},{"volume-title":"Proceedings of the USENIX Annual Technical Conference. USENIX Association, 1--14","author":"Sugerman J.","key":"e_1_2_1_43_1","unstructured":"Sugerman , J. , Venkitachalam , G. , and Lim , B . -H. 2001. Virtualizing I\/O devices on vmware workstation\u2019s hosted virtual machine monitor . In Proceedings of the USENIX Annual Technical Conference. USENIX Association, 1--14 . Sugerman, J., Venkitachalam, G., and Lim, B.-H. 2001. Virtualizing I\/O devices on vmware workstation\u2019s hosted virtual machine monitor. In Proceedings of the USENIX Annual Technical Conference. USENIX Association, 1--14."},{"key":"e_1_2_1_44_1","first-page":"3107","volume-title":"Antivirus scanning best practices guide. Tech. rep","author":"Sureshkumar N.","unstructured":"Sureshkumar , N. 2009. Antivirus scanning best practices guide. Tech. rep ., Network Appliance Inc . http:\/\/media.netapp.com\/documents\/tr- 3107 .pdf Sureshkumar, N. 2009. Antivirus scanning best practices guide. Tech. rep., Network Appliance Inc. http:\/\/media.netapp.com\/documents\/tr-3107.pdf"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/224057.224070"},{"key":"e_1_2_1_46_1","unstructured":"Tripwire. 2002. Tripwire open souce 2.3.1. http:\/\/ftp4.sf.net\/sourceforge\/tripwire\/tripwire-2.3.1-2.tar.gz. Tripwire . 2002. Tripwire open souce 2.3.1. http:\/\/ftp4.sf.net\/sourceforge\/tripwire\/tripwire-2.3.1-2.tar.gz."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/384268.378434"},{"key":"e_1_2_1_48_1","unstructured":"Weber R. O. 2004. Scsi object-based storage device commands (osd). ftp:\/\/ftp.t10.org\/t10\/drafts\/osd\/osd-r10.pdf. Weber R. O. 2004. Scsi object-based storage device commands (osd). ftp:\/\/ftp.t10.org\/t10\/drafts\/osd\/osd-r10.pdf."},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133373.1133423"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS.2006.92"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1880022.1880024","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1880022.1880024","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:52:15Z","timestamp":1750243935000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1880022.1880024"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,12]]},"references-count":47,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2010,12]]}},"alternative-id":["10.1145\/1880022.1880024"],"URL":"https:\/\/doi.org\/10.1145\/1880022.1880024","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"type":"print","value":"1094-9224"},{"type":"electronic","value":"1557-7406"}],"subject":[],"published":{"date-parts":[[2010,12]]},"assertion":[{"value":"2008-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-08-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2010-12-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}