CLS:一种支持状态图复用的攻击场景描述语言  被引量:3

CLS:An Attack Scenario Description Language Supporting State Diagram Reuse

在线阅读下载全文

作  者:齐德昱[1] 钱正平[1] 

机构地区:[1]华南理工大学计算机科学与工程学院,广州510640

出  处:《计算机科学》2006年第11期69-73,共5页Computer Science

基  金:"粤港关键领域重点突破项目"资助;项目编号:2005A10307007

摘  要:入侵检测描述语言是各种安全防护体系的核心,不仅影响到描述(检测)能力,而且影响执行效率。本文研究分析了国内外几种重要的入侵检测语言,提出了一种支持状态图复用的规则语言CLS。CLS简化了STATL的实现语义,通过组合状态图(实例)来达到同样的表达能力,以减少资源消耗,提高执行效率。CLS还针对网络入侵检测系统的需求,修改了STATL的状态、事件等静态语义元素,限制了其事件队列、代码块的功能,以简化实现。通过分析常见的网络协议层的攻击场景,我们建立了标准CLS扩展库,为用户进一步定制安全需求,提供了基本参考。The intrusion detection description language is the core component of various security protection systems. It determines the expressiveness (detecting ability) of a system and the running performance as well This paper investigates several major intrusion detection languages both at home and abroad and proposals a new language called CLS which supports state diagram reuse. CLS simplifies the semantic implementation of STATL through the composition of state diagrams (instances) to keep the expressiveness while reducing the resource cost and enhancing the running performance. CLS modifies some static semantic entities in STATL such as 'state' and 'event spec' and put some restrictions on ' event queue' and ' code block' in STATL in order to ease the implementation for network intrusion detection systems. Some scenarios of common attacks of network protocol layers are discussed and a standard CLS extension library is established, based on which users can design the actual security policy easily.

关 键 词:入侵检测 规则 状态转换 复用 语义 

分 类 号:TP312[自动化与计算机技术—计算机软件与理论]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象