An Application of Pattern Matching in Intrusion Detection
Sandeep S. Kumar, Eugene H. Spafford · Purdue e-Pubs (Purdue University System) · 1994
This report examines and classifies the characteristics of signatures used in misuse intrusion detection.EfficienL algorithms to matcll paHerns in some of these classes are described.A generalized model for matclling intrusion signatures based on Colored Petri Nets is presented, and some of its properties arc derived.Information flow can be controlled to provide more security; for example, the Bell LaPadula model [BL73], to provide secrecy, or the Biba model [Blb77], to provide integrity.However, there is a tradeoff between security and convenience of use.Both models are conservative and restrict read and write operations to ensure that the secrecy or the integrity of the system can never be compromised.Consequently, if both models arc jointly used, the resulting system will flag almost any useful operation as a breach of some security condition.Thus, a very secure system may not be useful.Furthermore, access controls -and protection models do not help in lhe case of insider threats or compromise of the authenticalion module.IT a weak password is broken, access control measures can do little to prevent stealing or corruption of information legally accessible to the compromised user.In general static methods of assuring properties in a system are overly restrictive and simply insufficient in some cases.Dynamic methods, for example behavior tracking, are therefore needed to detect and perhaps prevent breaches in security.Difficulties in Intrusion Detection using Pattern Matching a Several regular expression patterns, say Tel,"" Tern can be written as the regular expression (rell ... Ire m ) and matched approximately in O(mn) (page 36], where m is the total length of all the patterns.The oplimizations mentioned in that approach arc also applicable.