DocumentCode :
3359180
Title :
Automatic creation of models for network intrusion detection
Author :
Määttä, Marko ; Räty, Tomi
Author_Institution :
VTT Tech. Res. Centre of Finland, Oulu, Finland
fYear :
2012
fDate :
11-13 Jan. 2012
Firstpage :
231
Lastpage :
237
Abstract :
This paper proposes a tool which can create models for network intrusion detection. The created models are stored in Extensible Mark-up Language (XML) notation that describe packet level details, such as protocol header information, and in Message Sequence Chart (MSC) notation which is used for describing scenario information of network activities, for example describing a port scan with vulnerability exploitation attempt. The proposed tool will utilize Snort rules in the model creation process where a Snort rule is transformed into XML and MSC models. Besides Snort rules, the proposed tool is able to utilize network traffic traces stored in a packet capture format (Pcap). These traces may contain diverse set of different network activities that are relevant in gaining unauthorized access to computer systems or networks. Using these traces the proposed tool can create XML and MSC models that depict the malicious activities. The experimental utilization of the proposed tool will indicate that the XML and MSC models can be created fast and automatically using two separate sources and this will reduce the amount manual work required in the modelling process.
Keywords :
XML; computer network security; telecommunication traffic; MSC model; Snort rules; XML notation; computer network; computer system; extensible mark-up language notation; message sequence chart notation; network activity; network intrusion detection model; network traffic trace; packet capture format; protocol header information; unauthorized access; vulnerability exploitation attempt; Analytical models; Generators; IP networks; Intrusion detection; Protocols; Unified modeling language; XML; MSC; Modelling; Pcap; Snort rule; XML; network intrusion detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computing, Communications and Applications Conference (ComComAp), 2012
Conference_Location :
Hong Kong
Print_ISBN :
978-1-4577-1717-8
Type :
conf
DOI :
10.1109/ComComAp.2012.6154805
Filename :
6154805
Link To Document :
بازگشت