Publication:
A functional framework to evade network IDS

Loading...
Thumbnail Image
Identifiers
ISSN: 1530-1605
ISBN: 978-1-4244-9618-1
Publication date
2011-01
Defense date
Advisors
Tutors
Journal Title
Journal ISSN
Volume Title
Publisher
IEEE
Impact
Google Scholar
Export
Research Projects
Organizational Units
Journal Issue
Abstract
Signature based Network Intrusion Detection Systems (NIDS) apply a set of rules to identify hostile traffic in network segments. Currently they are so effective detecting known attacks that hackers seek new techniques to go unnoticed. Some of these techniques consist of exploiting network protocols ambiguities. Nowadays NIDS are prepared against most of these evasive techniques, as they are recognized and sorted out. The emergence of new evasive forms may cause NIDS to fail. In this paper we present an innovative functional framework to evade NIDS. Primary, NIDS are modeled accurately by means of Genetic Programming (GP). Then, we show that looking for evasions on models is simpler than directly trying to understand the behavior of NIDS. We present a proof of concept showing how to evade a self-built NIDS regarding two publicly available datasets. Our framework can be used to audit NIDS.
Description
Proceeding of: 44th Hawaii International Conference on System Science, Kauai, HI, January 4-7, 2011
Keywords
Network Intrusion Detection Systems, IDS, Evasion
Bibliographic citation
44th Hawaii International Conference on System Science. IEEE, 2011, pp. 1-10