Abstract. This paper presents the ADenoIdS intrusion detection system (IDS). ADenoIdS takes some architectural inspiration from the human immune system and automates intrusion recovery and attack signature extraction. These features are enabled through attack evidence detection. This IDS is initially designed to deal with application attacks, extracting signature for remote buffer overflow attacks. ADenoIdS is described in this paper and experimental results are also presented. These results show that ADenoIdS can discard false-positives and extract signatures which match the attacks.
F. S. de Paula, P. L. de Geus