Network Security White Papers
Automatic Generation and Analysis of NIDS Attacks
Overview A common way to elude a signature-based NIDS is to transform an attack instance that the NIDS recognizes into another instance that it misses. For example, to avoid matching the attack payload to a NIDS signature, attackers split the payload into several TCP packets or hide it between benign messages. It is observed that different attack instances can be derived from each other using simple transformations. The paper models these transformations as inference rules in a natural-deduction system. Starting from an exemplary attack instance, an inference engine to automatically generate all possible instances derived by a set of rules is used. The result is a simple yet powerful tool capable of both generating attack instances for NIDS testing and determining whether a given sequence of packets is an attack.
| Publisher | University of Wisconsin | File Format | |
|---|---|---|---|
| Date Published | September 2004 | ||
| Format | White Papers | ||
| Topics | |||



