Sciweavers

DIMVA
2010

KIDS - Keyed Intrusion Detection System

13 years 2 months ago
KIDS - Keyed Intrusion Detection System
Since most current network attacks happen at the application layer, analysis of packet payload is necessary for their detection. Unfortunately malicious packets may be crafted to mimic normal payload, and so avoid detection if the anomaly detection method is known. This paper proposes keyed packet payload anomaly detection NIDS. Model of normal payload is key dependent. Key is different for each implementation of the method and is kept secret. Therefore model of normal payload is secret although detection method is public. This prevents mimicry attacks. Payload is partitioned into words. Words are defined by delimiters. Set of delimiters plays a role of a key. Proposed design is implemented and tested. Testing with HTTP traffic confirmed the same detection capabilities for different keys.
Sasa Mrdovic, Branislava Drazenovic
Added 10 Feb 2011
Updated 10 Feb 2011
Type Journal
Year 2010
Where DIMVA
Authors Sasa Mrdovic, Branislava Drazenovic
Comments (0)