A Hierarchical Model for Distributed Attacks

Peng Ning,Sushil Jajodia,X. Sean Wang
DOI: https://doi.org/10.1007/978-1-4615-0467-2_6
2004-01-01
Abstract: In this chapter, we present a model to represent distributed attacks based on the concept of system view presented in Chapter 3. However, instead of developing a completely new model, we extend a model named ARMD [Lin et al., 1998, Lin, 1998], which was developed for host-based intrusion detection. There are several other models that could be used instead of ARMD, including rule based languages (e.g., P-BEST [Lindqvist and Porras, 1999] and RUSSEL [Mounji et al., 1995]), the State Transition Analysis Tool (STAT) [Il-gun et al., 1995, Vigna and Kermmerer, 1998, Vigna and Kemmerer, 1999], and the Colored Petri Automata (CPA) [Kumar, 1995, Kumar and Spafford, 1994].
What problem does this paper attempt to address?