Effective method for intrusion model reconstruction from execution-trace
Jianbin Li · Computer Engineering and Applications Journal · 2011
This paper proposes an efficient method to reconstruct the general network intrusion model from transcripts and instruction traces recorded during the intrusion via decompilation,enhanced formal analysis and verification techniques.In contrast to most current works focused on exploit signature generation,this method precisely models context-sensitive relations among malicious messages to reflect the intrusion dynamics,which has practical efficiency and provable soundness.In addition to detailed theoretical analysis,the engineering evaluation and application are also briefly presented.