Publication:
Modeling NIDS evasion with genetic programming

dc.affiliation.dptoUC3M. Departamento de Informáticaes
dc.affiliation.grupoinvUC3M. Grupo de Investigación: COSEC (Computer SECurity Lab)es
dc.contributor.authorPastrana, Sergio
dc.contributor.authorOrfila, Agustín
dc.contributor.authorRibagorda Garnacho, Arturo
dc.date.accessioned2010-11-17T12:31:44Z
dc.date.available2010-11-17T12:31:44Z
dc.date.issued2010-07
dc.descriptionProceeding of: 9th International Conference on Security and Management (SAM 2010). Las Vegas, Nevada, USA, July 12-15 2010
dc.description.abstractNowadays, Network Intrusion Detection Systems are quickly updated in order to prevent systems against new attacks. This situation has provoked that attackers focus their efforts on new sophisticated evasive techniques when trying to attack a system. Unfortunately, most of these techniques are based on network protocols ambiguities [1], so NIDS designers must take them into account when updating their tools. In this paper, we present a new approach to improve the task of looking for new evasive techniques. The core of our work is to model existing NIDS using the Genetic Pro- gramming paradigm. Thus, we obtain models that simulate the behavior of NIDS with great precision, but with a much simpler semantics than the one of the NIDS. Looking for this easier semantics allows us to easily construct evasions on the model, and therefore on the NIDS, as their behavior is quite similar. Our results show how precisely GP can model a NIDS behavior.
dc.description.statusPublicado
dc.format.mimetypeapplication/octet-stream
dc.format.mimetypeapplication/octet-stream
dc.format.mimetypeapplication/pdf
dc.identifier.bibliographicCitationProceedings of 9th International Conference on Security and Management (SAM 2010). Las Vegas, Nevada, USA.
dc.identifier.isbn1-60132-162-7
dc.identifier.publicationtitleProceedings of 9th International Conference on Security and Management (SAM 2010)
dc.identifier.urihttps://hdl.handle.net/10016/9673
dc.language.isoeng
dc.publisherCSREA Press
dc.relation.eventdateJuly 12-15 2010
dc.relation.eventnumber9
dc.relation.eventplaceLas Vegas (Nevada, USA)
dc.relation.eventtitleInternational Conference on Security and Management (SAM 2010)
dc.rights© CSREA Press
dc.rights.accessRightsopen access
dc.subject.ecienciaInformática
dc.subject.otherEvasion
dc.subject.otherIntrusion detection
dc.subject.otherNetwork security
dc.titleModeling NIDS evasion with genetic programming
dc.typeconference paper*
dc.type.reviewPeerReviewed
dspace.entity.typePublication
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Pastrana, Orfila, Ribagorda - 2010 - Modeling NIDS evasion with Genetic Programming - 9th In.pdf
Size:
396.96 KB
Format:
Adobe Portable Document Format