Colored Petri Nets as the Enabling Technology in Intrusion Detection Systems

被引:0
|
作者
Dolgikh, A. [1 ]
Nykodym, T. [1 ]
Skormin, V. [1 ]
Antonakos, J. [2 ]
Baimukhamedov, M. [3 ]
机构
[1] SUNY Binghamton, Binghamton, NY 13902 USA
[2] SUNY Broome Community Coll, Binghamton, NY 13901 USA
[3] Kostanai Tech Univ, Kostanai, Kazakhstan
关键词
behavior based IDS; Colored Petri Net; functionality detection; behavior detection;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Behavior based intrusion detection technologies are increasingly popular. Traditionally behavior patterns are expressed as specific signatures defined in the system call domain. This approach has various drawbacks and is vulnerable to possible obfuscations. The IDS approach discussed herein addresses process behavior in terms of functionalities, i.e. particular process objectives. The functionalities are formalized in the form that is independent of their specific realizations and is obfuscation resistant. The malware is detected by particular sets of functionalities exposed by programs during their execution. The approach implies the selection of common malicious functionalities, followed by formal description of these functionalities via specific system call combinations. In the detection domain, monitored system calls are combined into API functions utilizing Colored Petri nets (CPN). After that API functions are combined into malicious functionalities, indicative of malware attack, also using CPN. The advantages of CPN utilization for dynamic code analysis are described. By its nature the described approach is signature-based. The CPN technology is the backbone of the described approach: CPNs are used to define the functionalities of interests as behavior signatures, and at the same time serve as the mechanism for the signature detection. The paper describes a unique general-purpose software tool implementing CPN. It constitutes the enabling technology for the described IDS approach, and has many additional applications for modeling and monitoring complex hierarchical systems of discrete events.
引用
收藏
页码:1297 / 1301
页数:5
相关论文
共 50 条
  • [31] Simulation of Colored Time Petri Nets
    Zhang, Hongmei
    Liu, Fei
    Yang, Ming
    Li, Wei
    2013 IEEE INTERNATIONAL CONFERENCE ON INFORMATION AND AUTOMATION (ICIA), 2013, : 637 - 642
  • [32] Task Allocation Policy for UGV Systems using Colored Petri Nets
    Wang, Xiaojun
    Rui, Feng
    Hu, Hesuan
    2018 ANNUAL AMERICAN CONTROL CONFERENCE (ACC), 2018, : 3050 - 3055
  • [33] COORDINATION CONTROL OF FLEXIBLE MANUFACTURING SYSTEMS USING COLORED PETRI NETS
    MENON, SR
    QUINN, TJ
    FERREIRA, PM
    KAPOOR, SG
    FOURTH INTERNATIONAL CONFERENCE ON COMPUTER-AIDED PRODUCTION ENGINEERING, 1988, : 317 - 326
  • [34] Managing feature interactions in telecommunications systems by temporal colored Petri nets
    Lu, YQ
    Wei, G
    Cheung, TY
    SEVENTH IEEE INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS, PROCEEDINGS, 2001, : 260 - 269
  • [35] Modeling and analysis of embedded systems based on Extended Colored Petri Nets
    Li, B. (Libing_lyl@163.com), 1600, Advanced Institute of Convergence Information Technology, Myoungbo Bldg 3F,, Bumin-dong 1-ga, Seo-gu, Busan, 602-816, Korea, Republic of (04):
  • [36] MODELING AUTOMATED MANUFACTURING SYSTEMS USING A MODIFICATION OF COLORED PETRI NETS
    KOCHIKAR, VP
    NARENDRAN, TT
    ROBOTICS AND COMPUTER-INTEGRATED MANUFACTURING, 1992, 9 (03) : 181 - 189
  • [37] Colored stochastic Petri nets for modelling and analysis of multiclass retrial systems
    Gharbi, Nawel
    Dutheillet, Claude
    Ioualalen, Malika
    MATHEMATICAL AND COMPUTER MODELLING, 2009, 49 (7-8) : 1436 - 1448
  • [38] Modeling multi-agent systems with hierarchical colored Petri nets
    Ma, BX
    ARTIFICIAL INTELLIGENCE APPLICATIONS AND INNOVATIONS II, 2005, 187 : 167 - 171
  • [39] Colored Hybrid Petri-nets for modeling material handling systems
    Basile, Francesco
    Chiacchio, Pasquale
    Coppola, Jolanda
    2011 50TH IEEE CONFERENCE ON DECISION AND CONTROL AND EUROPEAN CONTROL CONFERENCE (CDC-ECC), 2011, : 5881 - 5886
  • [40] Modeling inheritance anomaly in concurrent systems using colored Petri nets
    Bauskar, B
    Mikolajczak, B
    2004 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN & CYBERNETICS, VOLS 1-7, 2004, : 4873 - 4878