A novel algorithm for intrusion detection based on RASL model checking (Q474447)
From MaRDI portal
| This is the item page for this Wikibase entity, intended for internal use and editing purposes. Please use this page instead for the normal view: A novel algorithm for intrusion detection based on RASL model checking |
scientific article; zbMATH DE number 6372848
| Language | Label | Description | Also known as |
|---|---|---|---|
| default for all languages | No label defined |
||
| English | A novel algorithm for intrusion detection based on RASL model checking |
scientific article; zbMATH DE number 6372848 |
Statements
A novel algorithm for intrusion detection based on RASL model checking (English)
0 references
24 November 2014
0 references
Summary: The interval temporal logic (ITL) model checking (MC) technique enhances the power of intrusion detection systems (IDSs) to detect concurrent attacks due to the strong expressive power of ITL. However, an ITL formula suffers from difficulty in the description of the time constraints between different actions in the same attack. To address this problem, we formalize a novel real-time interval temporal logic-real-time attack signature logic (RASL). Based on such a new logic, we put forward a RASL model checking algorithm. Furthermore, we use RASL formulas to describe attack signatures and employ discrete timed automata to create an audit log. As a result, RASL model checking algorithm can be used to automatically verify whether the automata satisfy the formulas, that is, whether the audit log coincides with the attack signatures. The simulation experiments show that the new approach effectively enhances the detection power of the MC-based intrusion detection methods for a number of telnet attacks, p-trace attacks, and the other sixteen types of attacks. And these experiments indicate that the new algorithm can find several types of real-time attacks, whereas the existing MC-based intrusion detection approaches cannot do that.
0 references
0 references
0 references
0.7403491139411926
0 references
0.6809020638465881
0 references
0.6787552237510681
0 references
0.6757352948188782
0 references
0.6725186705589294
0 references