KIDS: keyed intrusion detection system

  • Authors:
  • Sasa Mrdovic;Branislava Drazenovic

  • Affiliations:
  • University of Sarajevo, Faculty of Electrical Engineering, Sarajevo, Bosnia and Herzegovina;University of Sarajevo, Faculty of Electrical Engineering, Sarajevo, Bosnia and Herzegovina

  • Venue:
  • DIMVA'10 Proceedings of the 7th international conference on Detection of intrusions and malware, and vulnerability assessment
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Since most current network attacks happen at the application layer, analysis of packet payload is necessary for their detection. Unfortunately malicious packets may be crafted to mimic normal payload, and so avoid detection if the anomaly detection method is known. This paper proposes keyed packet payload anomaly detection NIDS. Model of normal payload is key dependent. Key is different for each implementation of the method and is kept secret. Therefore model of normal payload is secret although detection method is public. This prevents mimicry attacks. Payload is partitioned into words. Words are defined by delimiters. Set of delimiters plays a role of a key. Proposed design is implemented and tested. Testing with HTTP traffic confirmed the same detection capabilities for different keys.