A computer network defense-oriented scheme description language

Wei Zhao,Chunhe Xia,Yang Luo,Xiaochen Liu,Weikang Wu
DOI: https://doi.org/10.4028/www.scientific.net/AMR.765-767.1739
2013-01-01
Advanced Materials Research
Abstract:Existing defense policy description language can describe some aspects of defense only, such as protection or detection but cannot express relationship among actions. Thus, it cannot accomplish a joint defense goal with the linkage of all kinds of defense mechanism for large-scale, distributed network attacking, such as Botnet. To solve this problem, we proposed a computer network defense-oriented scheme description language (CNDSDL), which can describe protection, detection, analysis, response, and recover actions as well as relationship among actions. These relations include sequence-and, sequence-or, concurrent-and, concurrent-or, and xor. It provides a unified coupling language description for linkage defense of different security devices. At last, we realized the simulation of schemes which are described by CNDSDL. The experiment's results show that CNDSDL can be transformed to detailed technique rules and realize the defense effect of expression. © (2013) Trans Tech Publications, Switzerland.
What problem does this paper attempt to address?