Network Security White Papers

Automatic Generation and Analysis of NIDS Attacks

Overview A common way to elude a signature-based NIDS is to transform an attack instance that the NIDS recognizes into another instance that it misses. For example, to avoid matching the attack payload to a NIDS signature, attackers split the payload into several TCP packets or hide it between benign messages. It is observed that different attack instances can be derived from each other using simple transformations. The paper models these transformations as inference rules in a natural-deduction system. Starting from an exemplary attack instance, an inference engine to automatically generate all possible instances derived by a set of rules is used. The result is a simple yet powerful tool capable of both generating attack instances for NIDS testing and determining whether a given sequence of packets is an attack.

Further White Paper Details
PublisherUniversity of Wisconsin File FormatPDF
Date PublishedSeptember 2004
FormatWhite Papers   
Topics
E4 embraces web 2.0 audience

E4 embraces web 2.0 audience

Case study: How the Channel 4's teen channel put its mind to building a community website... more

Danone on health kick with Itil

Danone on health kick with Itil

Case study: Food company making IT easier to manage more

Cheat Sheet: Cloud computing

Cheat Sheet: Cloud computing

A tech storm is brewing...  more


Quick Sitemap Links: