首页> 外文期刊>International Journal on Software Tools for Technology Transfer >Using model checking to identify errors in intrusion detection signatures
【24h】

Using model checking to identify errors in intrusion detection signatures

机译:使用模型检查来识别入侵检测签名中的错误

获取原文
获取原文并翻译 | 示例
           

摘要

Most intrusion detection systems deployed today apply misuse detection as analysis method. Misuse detection searches for attack traces in the recorded audit data using predefined patterns. The matching rules are called signatures. The definition of signatures is up to now an empirical process based on expert knowledge and experience. The analysis success and accordingly the acceptance of intrusion detection systems in general depend essentially on the topicality of the deployed signatures. Methods for a systematic development of signatures have scarcely been reported yet, so the modeling of a new signature is a time-consuming, cumbersome, and error-prone process. The modeled signatures have to be validated and corrected to improve their quality. So far only signature testing is applied for this. Signature testing is still a rather empirical and time-consuming process to detect modeling errors. In this paper, we present the first approach for verifying signature specifications using the Spin model checker. The signatures are modeled in the specification language EDL, which leans on colored Petri nets. We show how the signature specification is transformed into a Promela model and how characteristic specification errors can be found by Spin.
机译:当前部署的大多数入侵检测系统都将滥用检测用作分析方法。滥用检测使用预定义的模式在记录的审核数据中搜索攻击痕迹。匹配规则称为签名。到目前为止,签名的定义是基于专家知识和经验的经验过程。分析的成功以及相应地入侵检测系统的接受通常基本上取决于所部署签名的时事性。尚未系统报道签名的系统开发方法,因此对新签名进行建模是一个耗时,麻烦且容易出错的过程。建模签名必须经过验证和纠正以提高其质量。到目前为止,仅对此进行签名测试。签名测试仍然是检测模型错误的经验和耗时的过程。在本文中,我们介绍了使用Spin模型检查器验证签名规范的第一种方法。签名以规范语言EDL建模,该语言依赖于彩色Petri网。我们展示了签名规范如何转换为Promela模型,以及Spin如何发现特征规范错误。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号