JISE


  [1] [2] [3] [4] [5] [6] [7]


Journal of Information Science and Engineering, Vol. 17 No. 6, pp. 899-919


An Instusion Detection Model Based Upon Intrusion Detection Markup Language (IDML)


Yao-Tsung Lin, Shian-Shyong Tseng and Shun-Chieh Lin
Department of Computer and Information Science 
National Chiao Tung University 
Hsinchu, 300 Taiwan 
E-mail: sstseng@cis.nctu.edu.tw


    Due to the rapid growth of networked computer resources and the increasing importance of related applications, intrusions which threaten the infrastructure of these applications have are critical problems. In recent years, several intrusion detection systems designed to identify and detect possible intrusion behaviors. In this work, an intrusion detection model is proposed to for building an intrusion detection system which can solve problems involved in building an intrusion detection systems, including pattern representation, computability, performance, extendibility and maintenance problems. In this model, IDML is first designed to express intrusion patterns, and these patterns are transformed into intrusion pattern state machines. Once the intrusion pattern state machines are obtained, the corresponding intrusion detection mechanism that can use these state machines to detect intrusions is designed. To evaluate the performance of our model, an IDML-based intrusion detection experimental system based upon this architecture has been implemented.


Keywords: intrusion detection, intrusion pattern, IDML, XML, finite state machine

  Retrieve PDF document (JISE_200106_03.pdf)