A Stream-Based Specification Language for Network Monitoring

A Stream-Based Specification Language for Network Monitoring
复制标题

DOI:
10.1007/978-3-319-46982-9_10
复制
发表时间:
2016-09
期刊:
--
影响因子:
--
通讯作者:
Peter Faymonville;B. Finkbeiner;Sebastian Schirmer;Hazem Torfah
Peter Faymonville;B. Finkbeiner;Sebastian Schirmer;Hazem Torfah
中科院分区:
其他
文献类型:
--
作者:
Peter Faymonville;B. Finkbeiner;Sebastian Schirmer;Hazem Torfah

文献摘要

被引文献

相似文献

我们引入了 Lola 2.0,一种基于流的规范语言,用于精确描述网络流量中的复杂安全属性。该语言扩展了规范语言 Lola 的两个新功能:模板流表达式(允许输入数据沿流传输)和动态流生成(在监视过程中可以调用新监视器,以在自己的时间尺度上监视新子任务)。 Lola 2.0 简单且富有表现力:它将 Snort 等基于规则的规范语言的易用性与以前描述复杂状态依赖性和统计度量所需的重量级脚本语言或时序逻辑的表现力结合在一起。 Lola 2.0 规范通过从输入流增量构造输出流来监控,同时维护部分计算表达式的存储。我们使用几个实际示例的原型实现来展示 Lola 2.0 的灵活性和表现力。
We introduce Lola 2.0, a stream-based specification language for the precise description of complex security properties in network traffic. The language extends the specification language Lola with two new features: template stream expressions, which allow input data to be carried along the stream, and dynamic stream generation, where new monitors can be invoked during the monitoring process for the monitoring of new subtasks on their own time scale. Lola 2.0 is simple and expressive: it combines the ease-of-use of rule-based specification languages like Snort with the expressiveness of heavy-weight scripting languages or temporal logics previously needed for the description of complex stateful dependencies and statistical measures. Lola 2.0 specifications are monitored by incrementally constructing output streams from input streams, while maintaining a store of partially evaluated expressions. We demonstrate the flexibility and expressivity of Lola 2.0 using a prototype implementation on several practical examples.