...
首页> 外文期刊>Information and software technology >A Model-based Aspect-oriented Framework For Building Intrusion-aware Software Systems
【24h】

A Model-based Aspect-oriented Framework For Building Intrusion-aware Software Systems

机译:基于模型的面向方面的框架,用于构建入侵感知软件系统

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Security is a critical issue for software systems, especially for those systems which are connected to networks and the Internet, since most of them suffer from various malicious attacks. Intrusion detection is an approach to protect software against such attacks. However, security vulnerabilities that are exploited by intruders cut across multiple modules in software systems and are difficult to address and monitor. These kinds of concerns, called cross-cutting concerns, can be handled by aspect-oriented software development (AOSD) for better modularization. A number of works have utilized AOSD to address security issues of software systems, but none of them has employed AOSD for intrusion detection. In this paper, we propose a model-based aspect-oriented framework for building intrusion-aware software systems. We model attack scenarios and intrusion detection aspects using an aspect-oriented Unified Modeling Language (UML) profile. Based on the UML model, the intrusion detection aspects are implemented and woven into the target system. The resulting target system has the ability to detect the intrusions automatically. We present an experimental evaluation by applying this framework for some of the most common attacks included in the Web Application Security Consortium (WASC) web security threat classification. The experimental results demonstrate that the framework is effective in specifying and implementing intrusion detection and can be applied for a wide range of attacks.
机译:对于软件系统,特别是对于那些连接到网络和Internet的系统而言,安全性是一个关键问题,因为它们大多数都遭受各种恶意攻击。入侵检测是一种保护软件免受此类攻击的方法。但是,入侵者利用的安全漏洞跨越了软件系统中的多个模块,并且很难解决和监视。可以通过面向方面的软件开发(AOSD)处理这些问题,称为横切关注点,以实现更好的模块化。许多工作已经利用AOSD来解决软件系统的安全问题,但是没有一个人使用AOSD进行入侵检测。在本文中,我们提出了一个基于模型的面向方面的框架,用于构建入侵感知软件系统。我们使用面向方面的统一建模语言(UML)配置文件对攻击场景和入侵检测方面进行建模。基于UML模型,入侵检测方面得以实现并被编织到目标系统中。生成的目标系统具有自动检测入侵的能力。我们通过将该框架应用于Web应用程序安全联盟(WASC)Web安全威胁分类中包含的一些最常见的攻击,来提供实验评估。实验结果表明,该框架可以有效地指定和实施入侵检测,并且可以应用于各种攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号