This commit is contained in:
Arthur Grisel-Davy 2023-07-21 13:15:05 -04:00
parent 22c1c5ef06
commit a4b484a433

View file

@ -633,7 +633,7 @@ The rules are formaly defined using the \gls{stl} syntax which is bespoke for de
1 & "SLEEP" state only & $R_1 := \square_{[0,1h]\cup [2h40,3h20]}(s[t]=0)$ & Machine takeover, Botnet\cite{mitre_botnet}, Rogue Employee\\
2 & Exactly one occurence of "REBOOT" & $R_2 := \lozenge(s[t]=3) \cup (\neg \square_{[,2h40]}(s[t]=3)$ & \gls{apt}\cite{mitre_prevent}, Backdoors\\
3 & No "HIGH" state for more than 30s. & $R_3 := \square (s[t_0]=2 \rightarrow \lozenge_{[t_0,t_0+30s]}(s[t]=2))$ & CryptoMining Malware \cite{mitre_crypto}, Ransomware\cite{mitre_ransomware}, BotNet\cite{mitre_botnet}\\
4 & No "REBOOT" occurence. & $R_4 := \neg \square_{[1h,2h40]}(s[t]=3)$ & Malware Installation\\
4 & No "SLEEP" for more than 8m. & $R_4 := \square (s[t_0]=0 \rightarrow \lozenge_{[t_0,t_0+1h]}(s[t]=0))$ & System Malfunction\\
\bottomrule
\end{tabular}
\label{tab:rules}