An interval temporal logic-based matching framework for finding occurrences of multi-event attack signatures

被引:1
|
作者
Nowicka, Elzbieta [1 ]
Zawada, Marcin [2 ]
机构
[1] Wroclaw Univ Technol, Chair Comp Syst & Networks, PL-50370 Wroclaw, Poland
[2] Wroclaw Univ Technol, Inst Math & Comp Sci, Wroclaw, Poland
关键词
intrusion detection; attack signatures; interval temporal logic; approximate pattern matching;
D O I
10.1007/978-3-540-73986-9_24
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Temporal logic has the potential to become a powerful mechanism for both modeling and detection of attack signatures. But, although recently some very expressive attack representations and on-line monitoring tools have been proposed, such tools still suffer from a lack of sufficiently precise detection mechanisms. In particular, they can report only the existence of an attack instance and cannot locate precisely its occurrence in a monitored event stream. Precise location is a key to enabling proper verification and identification of an attack. In this paper, we propose a formal framework for multi-event attack signature detection, based on Interval Temporal Logic. Our framework formalizes the problem of finding the localizations of a number types of attack signature occurrences: the first, all, k-insertion and the shortest one. In our approach, we use the existing run-time monitoring mechanism developed for the EAGLE specification, and extend it by special rules to enable such localization tasks. Our approach works on-line, and our initial results demonstrate the effectiveness and efficiency of the proposed approach.
引用
收藏
页码:272 / +
页数:3
相关论文
共 22 条
  • [1] Signal Temporal Logic-Based Attack Detection in DC Microgrids
    Beg, Omar Ali
    Nguyen, Luan V.
    Johnson, Taylor T.
    Davoudi, Ali
    IEEE TRANSACTIONS ON SMART GRID, 2019, 10 (04) : 3585 - 3595
  • [2] A Temporal Logic-Based Measurement Framework for Process Mining
    Cecconi, Alessio
    De Giacomo, Giuseppe
    Di Ciccio, Claudio
    Maggi, Fabrizio Maria
    Mendling, Jan
    2020 2ND INTERNATIONAL CONFERENCE ON PROCESS MINING (ICPM 2020), 2020, : 113 - 120
  • [3] Provenance Logic: Enabling Multi-Event Based Trust in Mobile Sensing
    Wang, Xinlei
    Fu, Hao
    Xu, Chao
    Mohapatra, Prasant
    2014 IEEE INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2014,
  • [4] A TEMPORAL LOGIC-BASED MODEL OF EVENT-DRIVEN NETS
    CINGEL, V
    FRISTACKY, N
    REAL-TIME SYSTEMS, 1991, 3 (04) : 407 - 428
  • [5] A logic-based framework for mobile multi-agent systems
    Kawamura, T
    Kinoshita, S
    Sugahara, K
    Kuwatani, T
    INTERNATIONAL CONFERENCE ON INTEGRATION OF KNOWLEDGE INTENSIVE MULTI-AGENT SYSTEMS: KIMAS'03: MODELING, EXPLORATION, AND ENGINEERING, 2003, : 754 - 759
  • [6] A multi-attribute and logic-based framework of ontology alignment
    Pietranik, Marcin
    Nguyen, Ngoc Thanh
    Advances in Intelligent Systems and Computing, 2013, 183 AISC : 99 - 108
  • [7] Implementation of a logic-based multi agent framework on Java']Java environment
    Kawamura, T
    Motomura, S
    Sugahara, K
    2005 INTERNATIONAL CONFERENCE ON INTEGRATION OF KNOWLEDGE INTENSIVE MULTI-AGENT SYSTEMS: KIMAS'05: MODELING, EXPLORATION, AND ENGINEERING, 2005, : 486 - 491
  • [8] A temporal logic-based planning and execution monitoring framework for unmanned aircraft systems
    Patrick Doherty
    Jonas Kvarnström
    Fredrik Heintz
    Autonomous Agents and Multi-Agent Systems, 2009, 19 : 332 - 377
  • [9] A temporal logic-based planning and execution monitoring framework for unmanned aircraft systems
    Doherty, Patrick
    Kvarnstrom, Jonas
    Heintz, Fredrik
    AUTONOMOUS AGENTS AND MULTI-AGENT SYSTEMS, 2009, 19 (03) : 332 - 377
  • [10] FADS: A framework for autonomous drone safety using temporal logic-based trajectory planning
    Pant, Yash Vardhan
    Li, Max Z.
    Rodionova, Alena
    Quaye, Rhudii A.
    Abbas, Houssam
    Ryerson, Megan S.
    Mangharam, Rahul
    TRANSPORTATION RESEARCH PART C-EMERGING TECHNOLOGIES, 2021, 130