A Software Architecture to Support Misuse Intrusion Detection

A Software Architecture to Support Misuse Intrusion Detection
复制标题

DOI:
--
复制
发表时间:
1995
期刊:
--
影响因子:
--
通讯作者:
Sandeep Kumar;E. Spafford
Sandeep Kumar;E. Spafford
中科院分区:
其他
文献类型:
--
作者:
Sandeep Kumar;E. Spafford

文献摘要

被引文献

相似文献

误用入侵检测在文献中传统上被理解为对计算机系统滥用的特定的、精确的表示技术的检测。模式匹配是很好的倾向于表示和检测这种滥用。每种特定的滥用方法都可以表示为一种模式,其中许多可以同时与内核生成的审计日志相匹配。使用相对高级别的模式来指定计算机系统滥用使模式编写者不必理解模式匹配的复杂性并将其编码到误用检测器中。图案代表。一种声明性的方式来指定需要检测什么,而不是指定应该如何检测。我们已经设计了一个模型的匹配基于有色Petri网专门针对误用入侵检测。在本文中,我们提出了一个软件架构结构的模式匹配解决方案,误用入侵检测。在一个面向对象的原型实现的上下文中,我们描述了封装通用功能和类之间的相互关系的抽象类。
Misuse Intrusion Detecl.ion has traditionally been understood in the literature as the detection of specific, precisely representable techniques of computer system abuse. Pattern matching is well disposed to the representation and detection of such abuse. Each specific method of abuse can be represented as a pattern and many of these can be matched simultaneously against the audit logs generated by the as kernel. Using relatively high level patterns to specify computer system abuse relieves the pattern writer from having to understand and encode the intricacies of pattern matching into a misuse detector. Patterns represent. a declarative way ofspecifying what needs Lo be detected, instead of specifying how it should be detected. We have devised a model of matching based on Colored Petri Nets specifically targeted for misuse intrusion detection. In this paper we present a software architecture for structuring a pattern matching solution to misuse intrusion detection. In the context of an object oriented prototype implementation we describe the abstract classes encapsulating generic functionality and the inter-relationships between the classes.