Network Security White Papers

Backtracking Algorithmic Complexity Attacks Against a NIDS

Overview Network Intrusion Detection Systems (NIDS) have become crucial to securing modern networks. To be effective, a NIDS must be able to counter evasion attempts and operate at or near wire-speed. Failure to do so allows malicious packets to slip through a NIDS undetected. This paper explores NIDS evasion through algorithmic complexity attacks. The paper presents a highly effective attack against the Snort NIDS, and the paper provides a practical algorithmic solution that successfully thwarts the attack. This attack exploits the behavior of rule matching, yielding inspection times that are up to 1.5 million times slower than that of benign packets. The analysis shows that this attack is applicable to many rules in Snort's ruleset, rendering vulnerable the thousands of networks protected by it.

Further White Paper Details
PublisherUniversity of Wisconsin File FormatPDF
Date PublishedSeptember 2006
FormatWhite Papers   
Topics
E4 embraces web 2.0 audience

E4 embraces web 2.0 audience

Case study: How the Channel 4's teen channel put its mind to building a community website... more

Danone on health kick with Itil

Danone on health kick with Itil

Case study: Food company making IT easier to manage more

Cheat Sheet: Cloud computing

Cheat Sheet: Cloud computing

A tech storm is brewing...  more


Quick Sitemap Links: