首页> 外文会议>IFIP WG 6.1 International Conference on Formal Techniques for Networked and Distributed Systems(FORTE 2005); 20051002-05; Taipei(CT) >A Framework Based Approach for Formal Modeling and Analysis of Multi-level Attacks in Computer Networks
【24h】

A Framework Based Approach for Formal Modeling and Analysis of Multi-level Attacks in Computer Networks

机译:基于框架的计算机网络多层次攻击的形式化建模和分析方法

获取原文
获取原文并翻译 | 示例

摘要

Attacks on computer networks are moving away from simple vulnerability exploits. More sophisticated attack types combine and depend on aspects on multiple levels (e.g. protocol and network level). Furthermore attacker actions, regular protocol execution steps, and administrator actions may be interleaved. Analysis based on human reasoning and simulation only has a slim chance to reveal attack possibilities. Formal methods are in principle well-suited in this situation. Since complex scenarios have to be considered, however, high efforts are needed for modeling. Furthermore, automated analysis tools usually fail due to state space explosion. We propose a novel approach for modeling and analyzing such scenarios. It combines the high-level specification language cTLA with a computer network framework, optimization strategies, a translation tool, and the SPIN model checker. As a proof of feasibility we apply our approach to a multi-LAN scenario.
机译:对计算机网络的攻击正在从简单的漏洞利用中转移。更复杂的攻击类型结合起来并取决于多个级别(例如协议和网络级别)的各个方面。此外,攻击者操作,常规协议执行步骤和管理员操作可能会交错。基于人为推理和模拟的分析只有很小的机会来揭示攻击可能性。在这种情况下,形式化方法原则上非常适合。但是,由于必须考虑复杂的场景,因此需要进行大量的建模工作。此外,自动分析工具通常由于状态空间爆炸而失败。我们提出了一种新颖的方法来对这种情况进行建模和分析。它将高级规范语言cTLA与计算机网络框架,优化策略,翻译工具和SPIN模型检查器结合在一起。作为可行性的证明,我们将我们的方法应用于多LAN场景。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号