STATE TRANSITION ANALYSIS - A RULE-BASED INTRUSION DETECTION APPROACH

STATE TRANSITION ANALYSIS - A RULE-BASED INTRUSION DETECTION APPROACH
复制标题

DOI:
10.1109/32.372146
复制
发表时间:
1995-03-01
影响因子:
7.4
通讯作者:
PORRAS, PA
PORRAS, PA
中科院分区:
计算机科学1区
文献类型:
--
作者:
ILGUN, K;KEMMERER, RA;PORRAS, PA

文献摘要

被引文献

相似文献

本文提出了一种实时表示和检测计算机入侵的新方法,称为状态转换分析,它将入侵建模为从初始安全状态到目标受损状态的一系列状态变化,状态转换图,入侵的图形表示,准确地确定穿透的要求和危害,并仅列出成功完成穿透所必须发生的关键事件,状态转换图是根据实际计算机系统的状态来编写的,这些图构成了一个基于规则的入侵检测专家系统的基础,称为状态转换分析工具(STAT)。本文还介绍了该专家系统的UNIX专用原型USTAT的设计和实现。该原型提供了一个进一步说明的整体设计和功能的入侵检测方法,最后,STAT的功能进行了比较,可比的入侵检测工具。
This paper presents a new approach to representing and detecting computer penetrations in real-time, The approach, called state transition analysis, models penetrations as a series of state changes that lead from an initial secure state to a target compromised state, State transition diagrams, the graphical representation of penetrations, identify precisely the requirements for and the compromise of a penetration and present only the critical events that must occur for the successful completion of the penetration, State transition diagrams are written to correspond to the states of an actual computer system, and these diagrams form the basis of a rule-based expert system for detecting penetrations, called the state transition analysis tool (STAT), The design and implementation of a UNIX-specific prototype of this expert system, called USTAT, is also presented, This prototype provides a further illustration of the overall design and functionality of this intrusion detection approach, Lastly, STAT is compared to the functionality of comparable intrusion detection tools.