...
首页> 外文期刊>IEEE Transactions on Software Engineering >State transition analysis: a rule-based intrusion detection approach
【24h】

State transition analysis: a rule-based intrusion detection approach

机译:状态转换分析:基于规则的入侵检测方法

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The paper presents a new approach to representing and detecting computer penetrations in real time. The approach, called state transition analysis, models penetrations as a series of state changes that lead from an initial secure state to a target compromised state. State transition diagrams, the graphical representation of penetrations, identify precisely the requirements for and the compromise of a penetration and present only the critical events that must occur for the successful completion of the penetration. State transition diagrams are written to correspond to the states of an actual computer system, and these diagrams form the basis of a rule based expert system for detecting penetrations, called the state transition analysis tool (STAT). The design and implementation of a Unix specific prototype of this expert system, called USTAT, is also presented. This prototype provides a further illustration of the overall design and functionality of this intrusion detection approach. Lastly, STAT is compared to the functionality of comparable intrusion detection tools.
机译:本文提出了一种实时表示和检测计算机渗透的新方法。这种称为状态转换分析的方法将渗透建模为一系列状态变化,这些状态变化从初始安全状态导致目标受损状态。状态转换图,即渗透的图形表示,可精确识别渗透的要求和危害,并仅显示成功完成渗透所必须发生的关键事件。状态转换图被编写为与实际计算机系统的状态相对应,这些图构成了用于检测渗透的基于规则的专家系统(称为状态转换分析工具(STAT))的基础。还介绍了该专家系统的特定于Unix的原型(称为USTAT)的设计和实现。该原型进一步说明了这种入侵检测方法的总体设计和功能。最后,将STAT与同类入侵检测工具的功能进行了比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号