• DocumentCode
    2829033
  • Title

    Detecting computer and network misuse through the production-based expert system toolset (P-BEST)

  • Author

    Lindqvist, Ulf ; Porras, Phillip A.

  • Author_Institution
    Dept. of Comput. Eng., Chalmers Univ. of Technol., Goteborg, Sweden
  • fYear
    1999
  • fDate
    1999
  • Firstpage
    146
  • Lastpage
    161
  • Abstract
    The paper describes an expert system development toolset called the Production-Based Expert System Toolset (P-BEST) and how it is employed in the development of a modern generic signature analysis engine for computer and network misuse detection. For more than a decade, earlier versions of P-BEST have been used in intrusion detection research and in the development of some of the most well known intrusion detection systems, but this is the first time the principles and language of P-BEST are described to a wide audience. We present rule sets for detecting subversion methods against which there are few defenses-specifically, SYN flooding and buffer overruns-and provide performance measurements. Together, these examples and performance measurements indicate that P-BEST based expert systems are well suited for real time misuse detection in contemporary computing environments. In addition, the simplicity of the P-BEST language and its close integration with the C programming language makes it easy to use while still being very powerful and flexible
  • Keywords
    authorisation; computer network management; expert system shells; programming environments; real-time systems; safety systems; signal processing; C programming language; P-BEST based expert systems; Production-Based Expert System Toolset; SYN flooding; buffer overruns; contemporary computing environments; expert system development toolset; intrusion detection systems; modern generic signature analysis engine; network misuse detection; performance measurements; production based expert system toolset; real time misuse detection; rule sets; subversion methods; Computer languages; Computer networks; Computer science; Engines; Expert systems; Floods; Intrusion detection; Laboratories; Measurement; Operating systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 1999. Proceedings of the 1999 IEEE Symposium on
  • Conference_Location
    Oakland, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-0176-1
  • Type

    conf

  • DOI
    10.1109/SECPRI.1999.766911
  • Filename
    766911