DocumentCode
3178286
Title
An attack signature model to computer security intrusion detection
Author
Cansian, Adriano M. ; Silva, Artur R A da ; De Souza, Marcelo
Author_Institution
Comput. Security Res. Lab, Sao Paulo State Univ., Brazil
Volume
2
fYear
2002
fDate
7-10 Oct. 2002
Firstpage
1368
Abstract
Internal and external computer network attacks or security threats occur according to standards and follow a set of subsequent steps, allowing us to establish profiles or patterns. This well-known behavior is the basis of signature analysis intrusion detection systems. This work presents a new attack signature model to be applied on network-based intrusion detection systems engines. The AISF (ACME! Intrusion Signature Format) model is built upon XML technology and works on intrusion signature handling and analysis, from storage to manipulation. Using this new model, the process of storing and analyzing information about intrusion signatures for further use by an IDS become a less difficult and standardized process.
Keywords
computer network management; hypermedia markup languages; military communication; security of data; telecommunication security; ACME! Intrusion Signature Format; AISF; IDS; XML technology; attack signature model; computer network attacks; computer security intrusion detection; military communication; network-based intrusion detection systems; security threats; Adaptive systems; Computer networks; Computer security; Engines; Information analysis; Information security; Intrusion detection; Protection; Safety; XML;
fLanguage
English
Publisher
ieee
Conference_Titel
MILCOM 2002. Proceedings
Print_ISBN
0-7803-7625-0
Type
conf
DOI
10.1109/MILCOM.2002.1179680
Filename
1179680
Link To Document