首页> 外文期刊>Mathematical Problems in Engineering >A Novel Algorithm for Intrusion Detection Based on RASL Model Checking
【24h】

A Novel Algorithm for Intrusion Detection Based on RASL Model Checking

机译:基于RASL模型检查的入侵检测新算法

获取原文
获取原文并翻译 | 示例
           

摘要

The interval temporal logic (ITL) model checking (MC) technique enhances the power of intrusion detection systems (IDSs) to detect concurrent attacks due to the strong expressive power of ITL. However, an ITL formula suffers from difficulty in the description of the time constraints between different actions in the same attack. To address this problem, we formalize a novel real-time interval temporal logic-real-time attack signature logic (RASL). Based on such a new logic, we put forward a RASL model checking algorithm. Furthermore, we use RASL formulas to describe attack signatures and employ discrete timed automata to create an audit log. As a result, RASL model checking algorithm can be used to automatically verify whether the automata satisfy the formulas, that is, whether the audit log coincides with the attack signatures. The simulation experiments show that the new approach effectively enhances the detection power of the MC-based intrusion detection methods for a number of telnet attacks, p-trace attacks, and the other sixteen types of attacks. And these experiments indicate that the new algorithm can find several types of real-time attacks, whereas the existing MC-based intrusion detection approaches cannot do that.
机译:由于ITL的强大表达能力,间隔时间逻辑(ITL)模型检查(MC)技术增强了入侵检测系统(IDS)检测并发攻击的能力。但是,ITL公式难以描述同一攻击中不同动作之间的时间约束。为了解决这个问题,我们将一种新颖的实时间隔时间逻辑-实时攻击签名逻辑(RASL)形式化。基于这种新逻辑,提出了一种RASL模型检查算法。此外,我们使用RASL公式描述攻击特征,并采用离散定时自动机来创建审核日志。结果,可以使用RASL模型检查算法来自动验证自动机是否满足公式,即审核日志是否与攻击签名一致。仿真实验表明,该新方法有效增强了基于MC的入侵检测方法对多种telnet攻击,p-trace攻击和其他16种攻击的检测能力。这些实验表明,新算法可以发现多种类型的实时攻击,而现有的基于MC的入侵检测方法无法做到这一点。

著录项

  • 来源
    《Mathematical Problems in Engineering》 |2013年第3期|621203.1-621203.10|共10页
  • 作者单位

    School of Information Engineering, Zhengzhou University, Zhengzhou, Henan 450001, China,MOE Key Laboratory of Grain Information Technology & Control, Henan University of Technology, Zhengzhou, Henan 450001, China;

    School of Information Engineering, Zhengzhou University, Zhengzhou, Henan 450001, China;

    MOE Key Laboratory of Grain Information Technology & Control, Henan University of Technology, Zhengzhou, Henan 450001, China;

    School of Computer Science, Xidian University, Xi'an, Shaanxi 710071, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号