Simplifying Signature Engineering by Reuse
نویسندگان
چکیده
Most intrusion detection systems deployed today apply misuse detection as detection procedure. Misuse detection compares the recorded audit data with predefined patterns, i.e. signatures. A signature is usually empirically developed based on experience and expert knowledge. Methods for a systematic development are scarcely reported yet. Automated approaches to reusing design and modeling decisions of available signatures also do not exist. This induces relatively long development times for signatures causing inappropriate vulnerability windows. In this paper we present an approach for systematic signature derivation. It is based on the reuse of existing signatures to exploit similarities with existing attacks for deriving a new signature. The approach is based on an iterative abstraction of signatures. Based on a weighted abstraction tree it selects those signatures or signature fragments, which are similar to the novel attack. Finally, we present a practical application of the approach using the signature description language EDL.
منابع مشابه
Cost-Effective Maintenance Tools for Proprietary Languages
Maintenance of proprietary languages and corresponding tooling is expensive. Postponing maintenance to reduce these costs is an often applied, short-term solution which eventually may lead to an unoperational toolset. This paper describes a case study carried out in cooperation with Lucent Technologies where maintenance cost is decreased by simplifying the development process of languages and t...
متن کاملA Full-Duplex, Dual-Polarization 10Gbps Radio over Fiber system with wavelength reuse for upstream signal
This study presents a full-duplex Radio-over-Fiber (RoF) system providing the users' wireless access with a bit rate of 10 Gbps over 40 GHz radio carrier. This system can be used in a centralized radio access network (C-RAN) architecture because we provide a fully analog front haul link between central station and base station. We can consider it as infrastructure between remote radio heads (RR...
متن کاملSupporting Component Oriented Development with Reusable Autonomous Classes
Reuse during development of software systems has long been touted as a mechanism of reducing costs, increasing quality and speeding up development. At the same time the ability to develop systems using a predominantly graphical approach has long been promised but has never really delivered. The described development approach aims to address both of these issues, by providing a development frame...
متن کاملModel Driven Software Product Line Process for Service/Component-Based Applications
The software reuse becomes the key for companies to improve development costs, time-to-market, and software quality. The Software Product Line Engineering (SPLE) and the Model Driven Engineering (MDE) are two new forms of software reuse. Software product lines are recognized as a successful approach to reuse in many domains (cars, printers, phones...) and especially in software development. Sof...
متن کاملSETHEO Goes Software Engineering: Application of ATP to Software Reuse
Reuse of approved software components has been identified as one of the key factors for successful software engineering projects. Although the reuse process also covers many non-technical aspects [9] we will restrict ourselves to the retrieval of software components (SCR) based on their formal specifications. Our system NORA/HAMMR 3 is based on a library of software components with associated s...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2006