Effective method for intrusion model reconstruction from execution-trace

Jianbin Li · Computer Engineering and Applications Journal · 2011

This paper proposes an efficient method to reconstruct the general network intrusion model from transcripts and instruction traces recorded during the intrusion via decompilation,enhanced formal analysis and verification techniques.In contrast to most current works focused on exploit signature generation,this method precisely models context-sensitive relations among malicious messages to reflect the intrusion dynamics,which has practical efficiency and provable soundness.In addition to detailed theoretical analysis,the engineering evaluation and application are also briefly presented.

Read the paper · More papers on PaperTik