Journal of Software, Vol 3, No 2 (2008), 15-22, Feb 2008
doi:10.4304/jsw.3.2.15-22

Intrusion Detection Prototype Based on ADM-Logic

Mehdi Talbi, Meriam Ben Ghorbel-Talbi, Mohamed Mejri

Abstract


Intrusion detection systems (IDS) are considered nowadays as one of the most important components in the security architecture of information systems. For a Misuse-based IDS, also known as signature based IDS, the efficiency of detection is highly correlated to the quality of signatures. It is therefore very important to select a suitable formal language that provides both high expressiveness and simplicity when specifying attack signatures. It is also fundamental to have a user friendly and automatic tool allowing the specification and the verification of these signatures. This paper shows the efficiency and the suitability of the ADM-logic as a formal language to specify properties characterizing a large variety of attack scenario, and focus on the design and implementation details of our intrusion detection prototype based on this logic.



Keywords


intrusion detection system, ADM-Logic, TCPIP based attacks

References



Full Text: PDF


Journal of Software (JSW, ISSN 1796-217X)

Copyright @ 2006-2012 by ACADEMY PUBLISHER – All rights reserved.