A Temporal Logic Based Framework for Intrusion Detection [chapter]

Prasad Naldurg, Koushik Sen, Prasanna Thati
2004 Lecture Notes in Computer Science  
We propose a framework for intrusion detection that is based on runtime monitoring of temporal logic specifications. We specify intrusion patterns as formulas in an expressively rich and efficiently monitorable logic called Eagle. Eagle supports data-values and parameterized recursive equations, and allows us to succinctly express security attacks with complex temporal event patterns, as well as attacks whose signatures are inherently statistical in nature. We use an online monitoring algorithm
more » ... that matches specifications of the absence of an attack, with system execution traces, and raises an alarm whenever the specification is violated. We present our implementation of this approach in a prototype tool, called Monid and report our results obtained by applying it to detect a variety of security attacks in log-files provided by DARPA.
doi:10.1007/978-3-540-30232-2_23 fatcat:6mkdtviarraj3k2von2gcdmzim