Real-Time Protocol Analysis for Detecting Link-State Routing Protocol Attacks

Research output: Contribution to journalArticlepeer-review

30 Citations (Scopus)

Abstract

A real-time knowledge-based network intrusion-detection model for a link-state routing protocol is presented for the OSPF protocol. This model includes three layers: a data process layer to parse packets and dispatch data; an event abstractor to abstract predefined real-time events for the link-state routing protocol; and an extended timed finite state machine to express the real-time behavior of the protocol engine and to detect intrusions by pattern matching. The timed FSM, called the JiNao Finite State Machine (JFSM) is extended from the conventional FSM with timed states, multiple timers, and time constraints on state transitions. The JFSM is implemented as a generator that can create any FSM by constructing the configuration file only. The results show that this approach is very effective for detecting real-time intrusions. Our approach can be extended for use in other network protocol intrusion-detection systems, especially for those with known attacks.

Original languageEnglish
Pages (from-to)1-36
Number of pages36
JournalACM Transactions on Information and System Security
Volume4
Issue number1
DOIs
Publication statusPublished - 2001

All Science Journal Classification (ASJC) codes

  • General Computer Science
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'Real-Time Protocol Analysis for Detecting Link-State Routing Protocol Attacks'. Together they form a unique fingerprint.

Cite this