首页> 外文OA文献 >Online network intrusion detection system using temporal logic and stream data processing
【2h】

Online network intrusion detection system using temporal logic and stream data processing

机译:使用时间逻辑和流数据处理的在线网络入侵检测系统

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

These days, the world are becoming more interconnected, and the Internet has dominated the ways to communicate or to do business. Network security measures must be taken to protect the organization environment. Among these security measures are the intrusion detection systems. These systems aim to detect the actions that attempt to compromise the confidentiality, availability, and integrity of a resource by monitoring the events occurring in computer systems and/or networks. The increasing amounts of data that are transmitted at higher and higher speed networks created a challenging problem for the current intrusion detection systems. Once the traffic exceeds the operational boundaries of these systems, packets are dropped. This means that some attacks will not be detected. In this thesis, we propose developing an online network based intrusion detection system by the combined use of temporal logic and stream data processing. Temporal Logic formalisms allow us to represent attack patterns or normal behaviour. Stream data processing is a recent database technology applied to flows of data. It is designed with high performance features for data intensive applications processing. In this work we develop a system where temporal logic specifications are automatically translated into stream queries that run on the stream database server and are continuously evaluated against the traffic to detect intrusions. The experimental results show that this combination was efficient in using the resources of the running machines and was able to detect all the attacks in the test data. Additionally, the proposed solution provides a concise and unambiguous way to formally represent attack signatures and it is extensible allowing attacks to be added. Also, it is scalable as the system can benefit from using more CPUs and additional memory on the same machine, or using distributed servers.
机译:如今,世界之间的联系越来越紧密,互联网已成为沟通或开展业务的主要方式。必须采取网络安全措施来保护组织环境。这些安全措施包括入侵检测系统。这些系统旨在通过监视计算机系统和/或网络中发生的事件来检测试图破坏资源的机密性,可用性和完整性的操作。在越来越高的速度网络上传输的数据量越来越大,这为当前的入侵检测系统提出了一个具有挑战性的问题。一旦流量超过这些系统的操作范围,数据包就会被丢弃。这意味着将不会检测到某些攻击。本文提出将时态逻辑与流数据处理相结合,开发基于在线网络的入侵检测系统。时间逻辑形式主义使我们能够代表攻击模式或正常行为。流数据处理是一种应用于数据流的最新数据库技术。它具有高性能功能,可用于数据密集型应用程序处理。在这项工作中,我们开发了一个系统,在该系统中,时态逻辑规范会自动转换为在流数据库服务器上运行的流查询,并会根据流量进行持续评估以检测入侵。实验结果表明,这种组合可以有效利用运行中机器的资源,并且能够检测出测试数据中的所有攻击。此外,所提出的解决方案提供了一种简洁明了的方式来正式表示攻击特征,并且可扩展,允许添加攻击。而且,它是可扩展的,因为系统可以在同一台计算机上使用更多的CPU和更多的内存,或者使用分布式服务器来受益。

著录项

  • 作者

    Ahmed A;

  • 作者单位
  • 年度 2000
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号