User loginNavigation |
archivesDSL for Streaming Network Traffic AnalysisThis just announced at usenix 12: Unfortunately, paper is paywalled and not much details are there. I love various DSLs if they are well designed. The interesting property about any sort of network security monitoring is that it can't take very long to reach a decision on whether an event or packet is good or bad. Not all systems have to be instant, but where they have, the configuration language is quite simple - just a selector of properties and comparison against known values (I oversimply here...). That said, there's ample room for research into slightly delayed responses - say 2 min to reach decision. Having a beautiful language would certainly help. Has anyone seen any related work? DSL for Streaming Network Traffic AnalysisThis just announced at usenix 12: Unfortunately, paper is paywalled and not much details are there. I love various DSLs if they are well designed. The interesting property about any sort of network security monitoring is that it can't take very long to reach a decision on whether an event or packet is good or bad. Not all systems have to be instant, but where they have, the configuration language is quite simple - just a selector of properties and comparison against known values (I oversimply here...). That said, there's ample room for research into slightly delayed responses - say 2 min to reach decision. Having a beautiful language would certainly help. Has anyone seen any related work? |
Browse archivesActive forum topics |
Recent comments
3 days 8 hours ago
4 days 5 hours ago
5 days 10 hours ago
5 days 10 hours ago
1 week 3 days ago
1 week 3 days ago
1 week 3 days ago
4 weeks 4 days ago
5 weeks 2 days ago
5 weeks 2 days ago