A formal method for attack modelling and detection
Data(s) |
2006
|
---|---|
Resumo |
This paper presents a formal methodology for attack modeling and detection for networks. Our approach has three phases. First, we extend the basic attack tree approach 1 to capture (i) the temporal dependencies between components, and (ii) the expiration of an attack. Second, using the enhanced attack trees (EAT) we build a tree automaton that accepts a sequence of actions from input stream if there is a traverse of an attack tree from leaves to the root node. Finally, we show how to construct an enhanced parallel automaton (EPA) that has each tree automaton as a subroutine and can process the input stream by considering multiple trees simultaneously. As a case study, we show how to represent the attacks in IEEE 802.11 and construct an EPA for it. |
Identificador | |
Publicador |
Rensselaer Polytechnic Institute |
Relação |
http://www.cs.rpi.edu/research/pdf/06-01.pdf Camtepe, Seyit Ahmet & Yener, Bulent (2006) A formal method for attack modelling and detection. Rensselaer Polytechnic Institute, New York. |
Fonte |
School of Electrical Engineering & Computer Science; Information Security Institute; Science & Engineering Faculty |
Palavras-Chave | #080303 Computer System Security #attack modelling #attack trees #formal methods |
Tipo |
Report |