Copyright © 2005 Elsevier B.V. All rights reserved.
Using data-independence in the analysis of intrusion detection systems
Available online 19 March 2005.
References and further reading may be available for this article. To view references and further reading you must purchase this article.
Abstract
In this paper we demonstrate the modelling and analysis of intrusion detection systems and their environment using the process algebra Communicating Sequential Processes and its model checker FDR. We show that this analysis can be used to discover attack strategies that can be used to blind an intrusion detection system, even a hypothetically perfect one that knows all the weaknesses of its protected host. We give an exhaustive analysis of all such attack possibilities. We discuss how to strengthen the intrusion detection systems to prevent these attacks, and finally we show how we can use data independence techniques to verify the corrected versions.
Keywords: Intrusion detection; Desynchronisation attacks; Communicating Sequential Processes; Model checking; Data independence







E-mail Article
Add to my Quick Links

Cited By in Scopus (1)






