• DocumentCode
    2855393
  • Title

    ACML: Capability Based Attack Modeling Language

  • Author

    Pandey, N.K. ; Gupta, S.K. ; Leekha, Shaveta ; Zhou, Jingmin

  • Author_Institution
    Indian Inst. of Technol. Delhi, Delhi
  • fYear
    2008
  • fDate
    8-10 Sept. 2008
  • Firstpage
    147
  • Lastpage
    154
  • Abstract
    In this paper, we propose attack capability modelling language (ACML) used for capability model proposed by Zhau et. al. is a specification and description language that has been utilized to express the capability gained by attacker at each step in the intrusion process. These capabilities have been defined using the IDS alerts. Moreover the language also provides for the specification of compete attack scenarios in terms of capabilities of the intruder. This, in turn, helps to determine the state of the system, in terms of the extent of infiltration. ACML helps to avoid ambiguity in capability specifications while sharing among developers. We also propose attack capability modelling framework (ACMF) which forms the basis of a capability model-based semi-automated alert correlation process, which has been used to detect and identify the attack scenarios from IDS alerts. The framework consists of the tools for the implementation of the algebraic structure of capability, as defined in Pandey et al., which are needed for the correlation algorithm. Additionally, the language also has features for customizing the definitions of these structures as well as for customizing the correlation algorithm. To verify the expressiveness of the language and its suitability in describing attack capability model, experimental result of standard benchmark has been discussed.
  • Keywords
    correlation methods; security of data; simulation languages; attack capability modelling language; capability model; description language; intrusion process; model-based semiautomated alert correlation process; Aggregates; Algebra; Humans; Information security; Intrusion detection; Specification languages; ACML; Attack language; Attack scenario; Capability model; Intrusion detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance and Security, 2008. ISIAS '08. Fourth International Conference on
  • Conference_Location
    Naples
  • Print_ISBN
    978-0-7695-3324-7
  • Type

    conf

  • DOI
    10.1109/IAS.2008.26
  • Filename
    4627077