A formal method for attack modelling and detection


Autoria(s): Camtepe, Seyit Ahmet; Yener, Bulent
Data(s)

2006

Resumo

This paper presents a formal methodology for attack modeling and detection for networks. Our approach has three phases. First, we extend the basic attack tree approach 1 to capture (i) the temporal dependencies between components, and (ii) the expiration of an attack. Second, using the enhanced attack trees (EAT) we build a tree automaton that accepts a sequence of actions from input stream if there is a traverse of an attack tree from leaves to the root node. Finally, we show how to construct an enhanced parallel automaton (EPA) that has each tree automaton as a subroutine and can process the input stream by considering multiple trees simultaneously. As a case study, we show how to represent the attacks in IEEE 802.11 and construct an EPA for it.

Identificador

http://eprints.qut.edu.au/58479/

Publicador

Rensselaer Polytechnic Institute

Relação

http://www.cs.rpi.edu/research/pdf/06-01.pdf

Camtepe, Seyit Ahmet & Yener, Bulent (2006) A formal method for attack modelling and detection. Rensselaer Polytechnic Institute, New York.

Fonte

School of Electrical Engineering & Computer Science; Information Security Institute; Science & Engineering Faculty

Palavras-Chave #080303 Computer System Security #attack modelling #attack trees #formal methods
Tipo

Report