首页> 外文会议>IEEE International Symposium on Software Reliability Engineering Workshops >BP-IDS: Using business process specification to leverage intrusion detection in critical infrastructures
【24h】

BP-IDS: Using business process specification to leverage intrusion detection in critical infrastructures

机译:BP-ID:使用业务流程规范利用关键基础设施的入侵检测

获取原文

摘要

Intrusion detection systems typically suffer from effectiveness problems, of being incapable of detecting new threats, or generating too many false alarms to be of any usefulness. Specification-based intrusion detection systems tackle these problems, exhibiting low false alarm rates and being able to detect new threats, however, they have been seldom used, because they require to completely specify every acceptable action of the monitored system. On the other hand, safety-critical systems would greatly benefit from effective intrusion detection systems, as they are often well specified from a business process point of view, which makes them specially suited for these systems, provided that one translates high-level business process specifications into intrusion detection rules. This paper proposes BP-IDS, a specification-based intrusion detection system that automatically performs this translation. BP-IDS was tested on a critical transportation infrastructure and was able to exhibit good detection results.
机译:入侵检测系统通常遭受有效性问题,无法检测到新的威胁,或产生太多误报以具有任何有用性。基于规范的入侵检测系统解决这些问题,呈现出低误报率并且能够检测到新的威胁,但是,它们很少使用,因为它们需要完全指定受监控系统的每个可接受的动作。另一方面,安全关键系统将极大地受益于有效的入侵检测系统,因为它们通常从业务流程的角度指定,这使得它们特别适合这些系统,只要一个翻译高级业务流程规范入侵检测规则。本文提出了BP-ID,一种基于规范的入侵检测系统,可自动执行此转换。 BP-ID在关键的运输基础设施上进行了测试,并且能够表现出良好的检测结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号