APPLICATION OF YACC IN NETWORK INTRUSION DETECTION

Huang Jinzhong,Zhu Miaoliang
DOI: https://doi.org/10.3969/j.issn.1000-386X.2011.10.001
2011-01-01
Abstract:A new method to implement server-program-based anomaly detection using YACC is proposed,in which normal server program behavior is represented by a context-free grammar carried Semantic Label.This method makes use of parser which is automatically generated by YACC as anomaly detecting engine,utilizes the Error-Handling interface and the Semantic subroutine of YACC to analyse anomalous event.Experimental results show that the method can not only detect effective various attacks exploiting vulnerabilities existing in server programs,but also analyses anomalous behavior and provides detailed information about the intrusion,and this capability is currently lacking in the same way.
What problem does this paper attempt to address?