Combating against attacks on encrypted protocols

Zubair Md Fadlullah*, Tarik Taleb, Nirwan Ansari, Kazuo Hashimoto, Yutake Miyake, Yoshiaki Nemoto, Nei Kato

*この研究の対応する著者

研究成果: Conference contribution

15 被引用数 (Scopus)

抄録

Attacks against encrypted protocols are becoming increasingly popular. They pose a serious challenge to the conventional Intrusion Detection Systems (IDSs) which heavily rely on inspecting the network packet fields and are consequently unable to monitor encrypted sessions. IDSs can be broadly categorized into two types: signature-based and anomaly-based IDSs. The signature-based IDSs rely on previous attack signatures but are often ineffective against new attacks. On the other hand, anomaly-based detection systems depend on detecting the change in the protocol behavior caused by an attack. The latter can be employed to detect novel attacks, and therefore are often preferred over their signature-based counterpart. In this paper, we envision an anomaly-based IDS which can detect attacks against popular encrypted protocols, such as SSH and SSL. The proposed system creates a normal behavior profile and uses nonparametric Cusum algorithm to detect deviation from the normal profile. Upon detecting an anomaly, the proposed mechanism generates an alert, sets a delay to the protocol response, and traces back the attacker. The effectiveness of the proposed detection scheme is verified via simulations.

本文言語English
ホスト出版物のタイトル2007 IEEE International Conference on Communications, ICC'07
ページ1211-1216
ページ数6
DOI
出版ステータスPublished - 2007
外部発表はい
イベント2007 IEEE International Conference on Communications, ICC'07 - Glasgow, Scotland, United Kingdom
継続期間: 2007 6月 242007 6月 28

出版物シリーズ

名前IEEE International Conference on Communications
ISSN(印刷版)0536-1486

Conference

Conference2007 IEEE International Conference on Communications, ICC'07
国/地域United Kingdom
CityGlasgow, Scotland
Period07/6/2407/6/28

ASJC Scopus subject areas

  • コンピュータ ネットワークおよび通信
  • 電子工学および電気工学

フィンガープリント

「Combating against attacks on encrypted protocols」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル