首页> 外文会议>International conference on runtime verification >A Stream-Based Specification Language for Network Monitoring
【24h】

A Stream-Based Specification Language for Network Monitoring

机译:用于网络监视的基于流的规范语言

获取原文

摘要

We introduce Lola 2.0, a stream-based specification language for the precise description of complex security properties in network traffic. The language extends the specification language Lola with two new features: template stream expressions, which allow input data to be carried along the stream, and dynamic stream generation, where new monitors can be invoked during the monitoring process for the monitoring of new subtasks on their own time scale. Lola 2.0 is simple and expressive: it combines the ease-of-use of rule-based specification languages like Snort with the expressiveness of heavy-weight scripting languages or temporal logics previously needed for the description of complex stateful dependencies and statistical measures. Lola 2.0 specifications are monitored by incrementally constructing output streams from input streams, while maintaining a store of partially evaluated expressions. We demonstrate the flexibility and expressivity of Lola 2.0 using a prototype implementation on several practical examples.
机译:我们引入Lola 2.0,这是一种基于流的规范语言,用于精确描述网络流量中的复杂安全属性。该语言通过两个新功能扩展了规范语言Lola:模板流表达式(允许输入数据沿流携带)和动态流生成(动态流生成),可以在监视过程中调用新的监视器以监视其上的新子任务自己的时间尺度。 Lola 2.0简单而富有表现力:它将基于规则的规范语言(如Snort)的易用性与以前用于描述复杂的状态依存关系和统计量度的重量级脚本语言或时态逻辑的表达能力相结合。通过从输入流中渐进地构造输出流,同时维护部分评估的表达式,可以监视Lola 2.0规范。我们使用一些实际示例的原型实现来演示Lola 2.0的灵活性和表达能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号