A Novel Algorithm for Intrusion Detection Based on RASL Model Checking

Joint Authors

Zhu, Weijun
Zhou, Qinglei
Yang, Weidong
Zhang, Haibin

Source

Mathematical Problems in Engineering

Issue

Vol. 2013, Issue 2013 (31 Dec. 2013), pp.1-10, 10 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2013-03-30

Country of Publication

Egypt

No. of Pages

10

Main Subjects

Civil Engineering

Abstract EN

The interval temporal logic (ITL) model checking (MC) technique enhances the power of intrusion detection systems (IDSs) to detect concurrent attacks due to the strong expressive power of ITL.

However, an ITL formula suffers from difficulty in the description of the time constraints between different actions in the same attack.

To address this problem, we formalize a novel real-time interval temporal logic—real-time attack signature logic (RASL).

Based on such a new logic, we put forward a RASL model checking algorithm.

Furthermore, we use RASL formulas to describe attack signatures and employ discrete timed automata to create an audit log.

As a result, RASL model checking algorithm can be used to automatically verify whether the automata satisfy the formulas, that is, whether the audit log coincides with the attack signatures.

The simulation experiments show that the new approach effectively enhances the detection power of the MC-based intrusion detection methods for a number of telnet attacks, p-trace attacks, and the other sixteen types of attacks.

And these experiments indicate that the new algorithm can find several types of real-time attacks, whereas the existing MC-based intrusion detection approaches cannot do that.

American Psychological Association (APA)

Zhu, Weijun& Zhou, Qinglei& Yang, Weidong& Zhang, Haibin. 2013. A Novel Algorithm for Intrusion Detection Based on RASL Model Checking. Mathematical Problems in Engineering،Vol. 2013, no. 2013, pp.1-10.
https://search.emarefa.net/detail/BIM-1010120

Modern Language Association (MLA)

Zhu, Weijun…[et al.]. A Novel Algorithm for Intrusion Detection Based on RASL Model Checking. Mathematical Problems in Engineering No. 2013 (2013), pp.1-10.
https://search.emarefa.net/detail/BIM-1010120

American Medical Association (AMA)

Zhu, Weijun& Zhou, Qinglei& Yang, Weidong& Zhang, Haibin. A Novel Algorithm for Intrusion Detection Based on RASL Model Checking. Mathematical Problems in Engineering. 2013. Vol. 2013, no. 2013, pp.1-10.
https://search.emarefa.net/detail/BIM-1010120

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1010120