STATE TRANSITION ANALYSIS - A RULE-BASED INTRUSION DETECTION APPROACH

被引:311
作者
ILGUN, K
KEMMERER, RA
PORRAS, PA
机构
[1] UNIV CALIF SANTA BARBARA,DEPT COMP SCI,RELIABLE SOFTWARE GRP,SANTA BARBARA,CA 93106
[2] ADV COMP COMMUN,SANTA BARBARA,CA 93117
[3] AEROSP CORP,DEPT TRUSTED COMP SYST,LOS ANGELES,CA 90009
关键词
SECURITY; INTRUSION DETECTION; EXPERT SYSTEMS;
D O I
10.1109/32.372146
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents a new approach to representing and detecting computer penetrations in real-time, The approach, called state transition analysis, models penetrations as a series of state changes that lead from an initial secure state to a target compromised state, State transition diagrams, the graphical representation of penetrations, identify precisely the requirements for and the compromise of a penetration and present only the critical events that must occur for the successful completion of the penetration, State transition diagrams are written to correspond to the states of an actual computer system, and these diagrams form the basis of a rule-based expert system for detecting penetrations, called the state transition analysis tool (STAT), The design and implementation of a UNIX-specific prototype of this expert system, called USTAT, is also presented, This prototype provides a further illustration of the overall design and functionality of this intrusion detection approach, Lastly, STAT is compared to the functionality of comparable intrusion detection tools.
引用
收藏
页码:181 / 199
页数:19
相关论文
共 33 条
[1]  
Anderson J.P., 1980, COMPUTER SECURITY TH
[2]  
BISHOP M, 1982, SECURITY PROBLEM UNI
[3]  
CHEN K, 1990, MAY P IEEE S RES SEC, P278
[4]  
DEBAR H, 1992, MAY P IEEE S RES SEC, P240
[5]  
Denning D.E., 1985, REQUIREMENTS MODEL I
[6]  
DISCOLO AV, 1985, 42 BSD UNIX SECURITY
[7]  
FARMER D, 1990, 1990 P SUMM US C AN, P305
[8]  
GARVEY TD, 1991, 14TH NATIONAL COMPUTER SECURITY CONFERENCE - INFORMATION SYSTEMS SECURITY: REQUIREMENTS & PRACTICES, PROCEEDINGS, VOLS 1 AND 2, P372
[9]  
HALME LR, 1985, TR85012 SYT TECH REP
[10]  
HUBBARD B, 1990, RADCTR90413 TRUST IN