A Coalgebra as an Intrusion Detection System

In this paper we construct a coalgebra for an intrusion detection system to describe the behaviour of a packet stream together with selected actions in the case of intrusions. We start with an extension of the notion of the many-typed signature to the generalised signature and we construct the category of packets as a basic structure of our approach. A defined endofunctor captures the expected behaviour of the packet stream. The constructed coalgebra enables the description of the behaviour of the packet stream together with the reaction to intrusions.