Español English Contacte con nosotros http://www.uc3m.es/portal/page/portal/biblioteca
DSpace e-Archivo

Archivo Abierto Institucional de la Universidad Carlos III de Madrid > Investigación > Departamentos > Departamento de Informática > Grupo de Seguridad de las Tecnologías de la Información y de las Comunicaciones > DI - SETI - Artículos de Revistas >

Please use this identifier to cite or link to this item: http://hdl.handle.net/10016/12710

Google™ Scholar. Others By: Gascón, Hugo - Orfila, Agustín - Blasco, Jorge
Files in This Item:
update delays.PDF504,66 kBAdobe PDFformato pdf
Title: Analysis of update delays in signature-based network intrusion detection systems
Author(s): Gascón, Hugo
Orfila, Agustín
Blasco, Jorge
Publisher: Elsevier
Issued date: 2011
URI: http://hdl.handle.net/10016/12710
ISSN: 01674048
DOI: 10.1016/j.cose.2011.08.010
Abstract: Network Intrusion Detection Systems (NIDS) monitor network traffic looking for attempts to compromise the security of the system they protect. Signature-based NIDS rely on a set of known attack patterns to match malicious traffic. Accordingly, they are unable to detect a specific attack until a specific signature for the corresponding vulnerability is created, tested, released and deployed. Although vital, the delay in the updating process of these systems has not been studied in depth. This paper presents a comprehensive statistical analysis of this delay in relation to the vulnerability disclosure time, the updates of vulnerability detection systems (VDS), the software patching releases and the publication of exploits. The widely deployed NIDS Snort and its detection signatures release dates have been used. Results show that signature updates are typically available later than software patching releases. Moreover, Snort rules are generally released within the first 100 days from the vulnerability disclosure and most of the times exploits and the corresponding NIDS rules are published with little difference. Implications of these results are drawn in the context of security policy definition. This study can be easily kept up to date due to the methodology used.
Publisher version: http://dx.doi.org/10.1016/j.cose.2011.08.010
Keywords: Intrusion detection
vulnerability
signature update
exploit
patch
NIDS
VDS
Snort
Nessus
Rights: © Elsevier
Appears in Collections:DI - SETI - Artículos de Revistas

Refworks Export

SFX Query

Items in E-Archivo are protected by copyright, with all rights reserved, unless otherwise indicated.

 

Valid XHTML 1.0! © Universidad Carlos III de Madrid - Software DSpace - Terms of use - Feedback