ASAX: Software Architecture and Rule-Based Language for Universal Audit Trail Analysis

作者: Naji Habra , Baudouin Le Charlier , Abdelaziz Mounji , Isabelle Mathieu

DOI: 10.1007/BFB0013912

关键词:

摘要: After a brief survey of the problems related to audit trail analysis and some approaches deal with them, paper outlines project ASAX which aims at providing an advanced tool support such analysis. One key feature is its elegant architecture build on top universal allowing any be analysed after straight format adaptation. Another language RUSSEL used express queries trails. rulebased tailor-made for sequential files in one only pass. The conception makes good compromise respect needed efficiency hand suitable declarative look other hand. illustrated by examples rules detection representative classical security breaches.

参考文章(7)
T.F. Lunt, R. Jagannathan, R. Lee, A. Whitehurst, S. Listgarten, Knowledge-based intrusion detection [1989] Proceedings. The Annual AI Systems in Government Conference. pp. 102- 107 ,(1989) , 10.1109/AISIG.1989.47311
N Habra, Computer-aided prototyping: transformational approach Information & Software Technology. ,vol. 33, pp. 685- 697 ,(1991) , 10.1016/0950-5849(91)90042-A
R. D. Tennent, Principles of Programming Languages Prentice Hall PTR. ,(1981)
T.F. Lunt, Real-time intrusion detection Digest of Papers. COMPCON Spring 89. Thirty-Fourth IEEE Computer Society International Conference: Intellectual Leverage. pp. 348- 353 ,(1989) , 10.1109/CMPCON.1989.301954
D.E. Denning, An Intrusion-Detection Model IEEE Transactions on Software Engineering. ,vol. 13, pp. 222- 232 ,(1987) , 10.1109/TSE.1987.232894
T.F. Lunt, R. Jagannathan, A prototype real-time intrusion-detection expert system ieee symposium on security and privacy. pp. 59- 66 ,(1988) , 10.1109/SECPRI.1988.8098
R. Jagannathan, Ann Tamaru, Thomas D. Garvey, Teresa F. Lunt, Caveh Jalali, Fred Gilham, Harold S. Javitz, Peter G. Neumann, A REAL-TIME INTRUSION-DETECTION EXPERT SYSTEM (IDES) ,(1992)