Network Security White Papers

Combining Evasion Techniques to Avoid Network Intrusion Detection Systems

Overview Three different Network Intrusion Detection System (NIDS) evasion techniques were combined into a three-dimensional testing space. These evasion techniques manipulated the TCP/IP protocol instead of relying on application-specific evasions. A modified version of the Mendax program was used to send the ISAPI .printer attack in the clear to the target system. The evasion techniques used were segmentation of the attack into smaller packets, overlapping data in the packets, and the presence of "Presequence chaff". Derived from Mendax, presequence chaff places garbage data in the first packet, with sequence numbers less than session start. The testing space was run against a sample NIDS at three levels of sensitivity, showing regions where the combined evasion techniques were not correctly detected.

Further White Paper Details
PublisherSkaion File FormatPDF
Date PublishedMarch 2003
FormatWhite Papers   
Topics
E4 embraces web 2.0 audience

E4 embraces web 2.0 audience

Case study: How the Channel 4's teen channel put its mind to building a community website... more

Cheat Sheet: Cloud computing

Cheat Sheet: Cloud computing

A tech storm is brewing...  more


Quick Sitemap Links: