In this paper we extend our intrusion detection system ASAX with a deductive subsystem that allows us to assess the security level of a software configuration on a real time basis. By coupling the two subsystems - intrusion detection and configuration analysis - we moreover achieve a better tuning of the intrusion detection since the system has only to enable intrusion rules that are specifically required by the current state of the configuration.
Click Here to download this article