In this paper we present a storage based intrusion detection system (IDS) which uses time and space efficient point-intime copy and performs file system integrity checks to detect intrusions. The storage system software is enhanced to keep track of modified blocks such that the file system scan can be performed more efficiently. Furthermore, when an intrusion occurs a recent undamaged copy of the storage is used to recover the compromised data. Categories and Subject Descriptors H.3.2 [Information Storage and Retrieval]: Information Storage General Terms Security, Design, Experimentation Keywords Storage-based intrusion detection, file system integrity check
Mohammad Banikazemi, Dan E. Poff, Bülent Abal