Analysis of Timing Requirements for Intrusion Detection System
Jan Magott, Wroclaw University of Technology, Wroclaw, Poland
Marek Woda, Wroclaw University of Technology, Wroclaw, Poland
An Intrusion Detection System (IDS) is a collection of sensors (often in the form of mobile agents) that collect data (security related events), classify them and trigger an alarm when unwanted manipulations to regular network behaviour is detected. Activities of attackers and network are time dependent. In the paper, Fault Trees with Time Dependencies (FTTD) are used to describe intrusions with emphasis put on timing properties. In FTTD, events and gates are characterized by time parameters. FTTD are used in verification whether the IDS reacts sufficiently quick on the intrusions. As an example, ?The Victim trusts the Intruder? attack is analysed.
Citation:
Jan Magott, Pawel Skrobanek, Marek Woda, "Analysis of Timing Requirements for Intrusion Detection System," depcos-relcomex,pp.278-285, 2nd International Conference on Dependability of Computer Systems (DepCoS-RELCOMEX '07), 2007