Using constraints for intrusion detection: the NeMODe system

  • Authors:
  • Pedro Salgueiro;Daniel Diaz;Isabel Brito;Salvador Abreu

  • Affiliations:
  • Departamento de Informática, Universidade de Évora and CENTRIA FCT, UNL, Portugal;University of Paris 1-Sorbonne, Paris, France;Departamento de Engenharia, Escola Superior de Tecnologia e Gestão, Instituto Politécnico de Beja, Portugal;Departamento de Informática, Universidade de Évora and CENTRIA FCT, UNL, Portugal

  • Venue:
  • PADL'11 Proceedings of the 13th international conference on Practical aspects of declarative languages
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this work we present NeMODe a declarative system for Computer Network Intrusion detection which provides a declarative Domain Specific Language for describing computer network intrusion signatures that could spread across several network packets, which allows to state constraints over network packets, describing relations between several packets, and providing several back-end detection mechanisms which relies on Constraint Programming (CP) methodologies to find those intrusions.