The STAT tool suite

The STAT tool suite
复制标题

STAT 工具套件

DOI:
10.1109/discex.2000.821508
复制
发表时间:
2000
期刊:
Proceedings DARPA Information Survivability Conference and Exposition. DISCEX'00
影响因子:
--
通讯作者:
R. Kemmerer
R. Kemmerer
中科院分区:
--
文献类型:
--
作者:
Giovanni Vigna;S. T. Eckmann;R. Kemmerer

文献摘要

被引文献

相似文献

介绍了一套由加州大学圣巴巴拉分校(UCSB)的可靠软件小组开发的入侵检测工具。该工具套件基于状态转换分析技术(STAT),在该技术中,计算机渗透被指定为导致系统安全状态转换的一系列操作。这种通用的方法已经得到扩展和调整,可以在不同的领域和环境中执行入侵检测。最新的基于STAT的入侵检测系统是根据基于框架的方法开发的,最终的设计使用了一个“核心”模块,该模块体现了STAT方法的领域独立特征。该通用核心以定义良好的方式进行扩展,以实现针对不同领域和环境的入侵检测系统。该方法支持软件重用、可移植性和可扩展性,并允许对关键功能进行优化。
Describes a suite of intrusion detection tools developed by the Reliable Software Group at the University of California at Santa Barbara (UCSB). The tool suite is based on the state transition analysis technique (STAT), in which computer penetrations are specified as sequences of actions that cause transitions in the security state of a system. This general approach has been extended and tailored to perform intrusion detection in different domains and environments. The most recent STAT-based intrusion detection systems were developed following a framework-based approach, and the resulting design uses a "core" module that embodies the domain-independent characteristics of the STAT approach. This generic core is extended in a well-defined way to implement intrusion detection systems for different domains and environments. The approach supports software reuse, portability and extendibility, and it allows for the optimization of critical functionalities.