• DocumentCode
    3359180
  • Title

    Automatic creation of models for network intrusion detection

  • Author

    Määttä, Marko ; Räty, Tomi

  • Author_Institution
    VTT Tech. Res. Centre of Finland, Oulu, Finland
  • fYear
    2012
  • fDate
    11-13 Jan. 2012
  • Firstpage
    231
  • Lastpage
    237
  • Abstract
    This paper proposes a tool which can create models for network intrusion detection. The created models are stored in Extensible Mark-up Language (XML) notation that describe packet level details, such as protocol header information, and in Message Sequence Chart (MSC) notation which is used for describing scenario information of network activities, for example describing a port scan with vulnerability exploitation attempt. The proposed tool will utilize Snort rules in the model creation process where a Snort rule is transformed into XML and MSC models. Besides Snort rules, the proposed tool is able to utilize network traffic traces stored in a packet capture format (Pcap). These traces may contain diverse set of different network activities that are relevant in gaining unauthorized access to computer systems or networks. Using these traces the proposed tool can create XML and MSC models that depict the malicious activities. The experimental utilization of the proposed tool will indicate that the XML and MSC models can be created fast and automatically using two separate sources and this will reduce the amount manual work required in the modelling process.
  • Keywords
    XML; computer network security; telecommunication traffic; MSC model; Snort rules; XML notation; computer network; computer system; extensible mark-up language notation; message sequence chart notation; network activity; network intrusion detection model; network traffic trace; packet capture format; protocol header information; unauthorized access; vulnerability exploitation attempt; Analytical models; Generators; IP networks; Intrusion detection; Protocols; Unified modeling language; XML; MSC; Modelling; Pcap; Snort rule; XML; network intrusion detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computing, Communications and Applications Conference (ComComAp), 2012
  • Conference_Location
    Hong Kong
  • Print_ISBN
    978-1-4577-1717-8
  • Type

    conf

  • DOI
    10.1109/ComComAp.2012.6154805
  • Filename
    6154805