This book constitutes the refereed proceedings of the 9th International Symposium on Recent Advances in Intrusion Detection, RAID 2006, held in Hamburg, Germany in September 2006.The 16 revised full papers presented were carefully reviewed and selected from 93 submissions. The papers are organized in topical sections on anomaly detection, attacks, system evaluation and threat assessment, malware collection and analysis, anomaly- and specification-based detection, and network intrusion detection.
Recent Advances in Intrusion Detection Anomaly Detection A Framework for the Application of Association Rule Intrusion Detection Infrastructures Mining in Large Behavioral Distance Measurement Using Hidden Markov Models Attacks Automated Discovery of Mimicry Attacks Allergy Attack Against Automatic Signature Generation Paragraph: Thwarting Signature Learning by Training Maliciously System Evaluation and Threat Assessment Anomaly Detector Performance Evaluation Using a Parameterized Environment Ranking Attack Graphs Using Hidden Markov Models to Evaluate the Risks of Intrusions Malware Collection and Analysis The Nepenthes Platform: An Efficient Approach to Collect Malware Automatic Handling of Protocol Dependencies and Reaction to 0-Da Attacks with ScriptGen Based Honeypots Fast and Evasive Attacks: Highlighting the Challenges Ahead Anomaly- and Specification-Based Detection Anagram: A Content Anomaly Detector Resistant to Mimicry Attack DEMEM: Distributed Evidence-Driven Message Exchange IntrusionDetection Model for MANET Network Intrusion Detection Enhancing Network Intrusion Detection with Integrated Sampling and Filtering WIND: Workload-Aware INtrusion Detection SafeCard: A Gigabit IPS on the Network Card Author Index