A network state based intrusion detection model
Shan Zheng, Peng Chen, Xu Ying, Xu Ke · 2002
This paper presents a new approach, called the network state based model, to describe intrusions and attacks. In the model which uses FA theory and can detect unknown attacks, the attacks and intrusions are described by the states and state transitions of network protocols and operating systems. First, the paper shows that the model is feasible for intrusion detection, and then describes the intrusion detection system using this model by common intrusion detection framework. Finally, the network state based model is compared with some other models.