F. Flammini, A. Gaglione, N. Mazzocca, C. Pragliola DETECT: a novel framework for the detection of attacks to critical infrastructures presented by Andrea Gaglione Dipartimento di Informatica e Sistemistica Università di Napoli “Federico II” Via Claudio 21, 80125 Napoli Email: [email_address] Web: http://wpage.unina.it/andrea.gaglione European Safety & Reliability Conference, ESREL’08 22-25 September 2008 , Valencia, Spain
Event: happening that occurs (in a system) at some location and at some point in time
Primitive Event: condition on a specific sensor Composite Event: combination of primitive events defined by means of proper operators Chakravarthy, S. & Mishra, D. 1994. Snoop: An expressive event specification language for active databases. Data Knowl. Eng. , Vol. 14, No. 1, pp. 1–26.
OR: E1 OR E2 occurs when at least one of its components (E1, E2) occurs
AND : E1 AND E2 occur when both of its component occurr
ANY: ANY(m, E1, E2, …, En), m<=n occur when m out of n distinct events specified in the expression occur
SEQ: E1 SEQ E2 occurs when E2 occurs provided that E1 is already occurred