Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
|
 |
From Declarative Signatures to Misuse IDS
| |
|
From Declarative Signatures to Misuse IDS
Jean-Philippe Pouzol7 and Mireille Ducasé7 
| (7) |
IRISA/INSA de Rennes - Campus Universitaire de Beaulieu, 35042 Rennes Cedex, France |
Abstract
In many existing misuse intrusion detection systems, intrusion signatures are very close to the detection algorithms. As a
consequence, they contain too many cumbersome details. Recent work have proposed declarative signature languages that raise
the level of abstraction when writing signatures. However, these languages do not always come with operational support. In
this article, we show how to transform such declarative signatures into operational ones. This process points out several
technical details which must be considered with care when performing the translation by hand, but which can be systematically
handled.
A signature specification language named Sutekh is proposed. Its declarative semantics is precisely described. To produce rules for existing rule-based IDS from Sutekh signatures, an algorithm, based on the construction of a state-transition diagram, is given.
Fulltext Preview (Small, Large)
 References secured to subscribers.
|
|
|
|
|
|