Network Security White Papers

Enhancing Byte-Level Network Intrusion Detection Signatures With Context

Overview Many Network Intrusion Detection Systems (NIDS) use byte sequences as signatures to detect malicious activity. While being highly efficient, they tend to suffer from a high false-positive rate. This paper develops the concept of contextual signatures as an improvement of string-based signature-matching. Rather than matching fixed strings in isolation, the paper augments the matching process with additional context. When designing an efficient signature engine for the NIDS Bro, the paper provides low-level context by using regular expressions for matching, and high-level context by taking advantage of the semantic information made available by Bro's protocol analysis and scripting language. Therewith, the paper greatly enhances the signature's expressiveness and hence the ability to reduce false positives.

Further White Paper Details
PublisherAssociation for Computing Machinery File FormatPDF
Date PublishedOctober 2003
FormatWhite Papers   
Topics
Thin clients switch on digitally excluded

Thin clients switch on digitally excluded

Case study: Digital inclusion project tackles social exclusion in Liverpool more

Renault goes multilingual

Renault goes multilingual

Case study: Translation tech turns docs into 23 languages… more


Quick Sitemap Links: