Publication:
A functional framework to evade network IDS

dc.affiliation.dptoUC3M. Departamento de Informáticaes
dc.affiliation.grupoinvUC3M. Grupo de Investigación: COSEC (Computer SECurity Lab)es
dc.contributor.authorPastrana, Sergio
dc.contributor.authorOrfila, Agustín
dc.contributor.authorRibagorda Garnacho, Arturo
dc.date.accessioned2011-09-23T11:51:32Z
dc.date.available2011-09-23T11:51:32Z
dc.date.issued2011-01
dc.descriptionProceeding of: 44th Hawaii International Conference on System Science, Kauai, HI, January 4-7, 2011
dc.description.abstractSignature based Network Intrusion Detection Systems (NIDS) apply a set of rules to identify hostile traffic in network segments. Currently they are so effective detecting known attacks that hackers seek new techniques to go unnoticed. Some of these techniques consist of exploiting network protocols ambiguities. Nowadays NIDS are prepared against most of these evasive techniques, as they are recognized and sorted out. The emergence of new evasive forms may cause NIDS to fail. In this paper we present an innovative functional framework to evade NIDS. Primary, NIDS are modeled accurately by means of Genetic Programming (GP). Then, we show that looking for evasions on models is simpler than directly trying to understand the behavior of NIDS. We present a proof of concept showing how to evade a self-built NIDS regarding two publicly available datasets. Our framework can be used to audit NIDS.
dc.description.sponsorshipThis work was partially supported by CDTI, Ministerio de Industria, Turismo y Comercio of Spain in collaboration with Telefonica I+D, Project SEGUR@ CENIT-2007 2004.
dc.description.statusPublicado
dc.format.mimetypetext/plain
dc.format.mimetypeapplication/pdf
dc.identifier.bibliographicCitation44th Hawaii International Conference on System Science. IEEE, 2011, pp. 1-10
dc.identifier.doi10.1109/HICSS.2011.12
dc.identifier.isbn978-1-4244-9618-1
dc.identifier.issn1530-1605
dc.identifier.publicationfirstpage1
dc.identifier.publicationlastpage10
dc.identifier.publicationtitle44th Hawaii International Conference on System Science
dc.identifier.urihttps://hdl.handle.net/10016/9987
dc.language.isoeng
dc.publisherIEEE
dc.relation.eventdateJanuary 4-7, 2011
dc.relation.eventnumber44
dc.relation.eventplaceKauai (Hawaii, USA)
dc.relation.eventtitle44th Hawaii International Conference on System Science
dc.relation.publisherversionhttp://dx.doi.org/10.1109/HICSS.2011.12
dc.rights© IEEE
dc.rights.accessRightsopen access
dc.subject.ecienciaInformática
dc.subject.otherNetwork Intrusion Detection Systems
dc.subject.otherIDS
dc.subject.otherEvasion
dc.titleA functional framework to evade network IDS
dc.typeconference paper*
dspace.entity.typePublication
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
functional_HICSS_2011_ps.pdf
Size:
495.34 KB
Format:
Adobe Portable Document Format