Generating a Real-Time Constraint Engine for Network Protocols - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

Generating a Real-Time Constraint Engine for Network Protocols

Résumé

In this paper, we present a practical approach to generate the constraint engine for an effective constraint-based intrusion detection system (IDS). The IDS framework was designed for safety-sensitive networks that involve limited-access closed networks such as the networks for command and control systems or Air Traffic Control (ATC) systems. The constraint engine generated by the framework supports real-time performance while ensuring the intended, normal behaviour of its target networks. We present the IDS framework in terms of its internal DSL representation as well as its transformation mechanisms to generate the constraint engine code. Comparing the autogenerated version against a manually implemented, optimized version of the constraint engine indicates no significant difference in terms of their performance.
Fichier principal
Vignette du fichier
484602_1_En_5_Chapter.pdf (691.89 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02294615 , version 1 (23-09-2019)

Licence

Paternité

Identifiants

Citer

Mohamed Sami Rakha, Fahim T. Imam, Thomas R. Dean. Generating a Real-Time Constraint Engine for Network Protocols. 12th IFIP International Conference on Information Security Theory and Practice (WISTP), Dec 2018, Brussels, Belgium. pp.44-60, ⟨10.1007/978-3-030-20074-9_5⟩. ⟨hal-02294615⟩
79 Consultations
42 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More