Using Constraints for Intrusion Detection: the NeMODe System

Abstract : In this work we present NeMODe a declarative system for Computer Network Intrusion detection which provides a declarative Domain Specific Language for describing computer network intrusion signatures that could spread across several network packets, which allows to state constraints over network packets, describing relations between several packets, and providing several back-end detection mechanisms which relies on Constraint Programming (CP) methodologies to find those intrusions.
Document type :
Conference papers
Complete list of metadatas

https://hal-paris1.archives-ouvertes.fr/hal-00663805
Contributor : Diane Diaz <>
Submitted on : Friday, January 27, 2012 - 3:52:09 PM
Last modification on : Friday, September 27, 2019 - 12:16:04 PM

Links full text

Identifiers

Collections

Citation

Pedro Salgueiro, Daniel Diaz, Isabel Brito, Salvador Abreu. Using Constraints for Intrusion Detection: the NeMODe System. 13th International Symposium, PADL 2011, Jan 2011, Austin, Texas, United States. pp.115-129, ⟨10.1007/978-3-642-18378-2_11⟩. ⟨hal-00663805⟩

Share

Metrics

Record views

181