Approach of Specification-based Mixed Intrusion Detection

Wei MU,Hua SONG,Yiqi Dai
DOI: https://doi.org/10.3969/j.issn.1000-3428.2005.09.049
2005-01-01
Abstract:This paper introduces an improved specification-based approach to process the network data. By constructing state machine and get information from it, this approach can contain both anomaly-based and misuse-based intrusion detection methods, and gain the better detection capability. The approach has been tested under the intrusion data published by Lincoln lab in this paper.
What problem does this paper attempt to address?