Journal of Software, Vol 3, No 6 (2008), 21-28, Jun 2008
doi:10.4304/jsw.3.6.21-28

Constraint-based Trend Template for Intrusion Detection

Md. Ahsan Habib, Krisna Prasad Pawdel, Mohammad Rajiullah, Prashanta Man Shrestha

Abstract


Intrusion detection systems (IDS) are special computer security tools which help detect intrusion attempts. Misuse based detection is one of the techniques which is used by IDS to recognize predefined attack signatures. Attack languages, also known as detection languages, are used to describe attack signatures. Detection languages should be simple, expressive and flexible enough to help encode event signature accurately and conveniently. This paper shows the effectiveness of constraint based Trend Template (TT) as an efficient detection language by encoding some attack scenarios and focusing on the Trend Detector which recognizes those signatures from intrusion data.



Keywords


Intrusion detection system (IDS), Trend Template (TT), Trend Detector, Snort, DARPA

References



Full Text: PDF


Journal of Software (JSW, ISSN 1796-217X)

Copyright @ 2006-2012 by ACADEMY PUBLISHER – All rights reserved.