首页> 外文会议>IEEE Symposium on Security and Privacy >Detecting computer and network misuse through the production-based expert system toolset (P-BEST)
【24h】

Detecting computer and network misuse through the production-based expert system toolset (P-BEST)

机译:通过基于生产的专家系统工具集(P-BEST)检测计算机和网络滥用

获取原文

摘要

This paper describes an expert system development toolset called the Production-Based Expert System Toolset (P-BEST) and how it is employed in the development of a modern generic signature-analysis engine for computer and network misuse detection. For more than a decade, earlier versions of P-BEST have been used in intrusion detection research and in the development of some of the most well-known intrusion detection systems, but this is the first time the principles and language of P-BEST aredescribed to a wide audience. We present rule sets for detecting subversion methods against which there are few defenses-specifically, SYN flooding and buffer overruns-and provide performance measurements. Together; these examples and performancemeasurements indicate that P-BEST-based expert systems are well suited for real-time misuse detection in contemporary computing environments. In addition, the simplicity of the P-BEST language and its close integration with the C programming languagemakes it easy to use while still being very powerful and flexible.
机译:本文介绍了一个名为基于生产的专家系统工具集(P-BOST)的专家系统开发工具集以及如何在用于计算机和网络滥用检测的现代通用签名 - 分析引擎的开发中。十多年来,早期版本的P-BEST已被用于入侵检测研究和一些最着名的入侵检测系统的开发,但这是第一次P-BEET被遗产的原则和语言到广泛的受众。我们呈现了用于检测颠覆方法的规则集,特别是防御,特别是SYN泛洪和缓冲区溢出 - 并提供性能测量。一起;这些示例和表演表明,基于P-Best的专家系统非常适合当代计算环境中的实时滥用检测。此外,P-Best语言的简单性及其与C编程语言的密切集成易于使用,同时仍然非常强大,灵活。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号