Mimicry attacks on host-based intrusion detection systems

Mimicry attacks on host-based intrusion detection systems
复制标题

DOI:
10.1145/586110.586145
复制
发表时间:
2002-11
期刊:
--
影响因子:
--
通讯作者:
D. Wagner;Paolo Soto
D. Wagner;Paolo Soto
中科院分区:
其他
文献类型:
--
作者:
D. Wagner;Paolo Soto

文献摘要

被引文献

相似文献

我们研究了几个基于主机的异常检测系统,并研究其对规避攻击的安全性。首先,我们介绍了模仿攻击的概念,它允许一个老练的攻击者掩盖他们的入侵,以避免检测到的IDS。然后,我们开发了一个理论框架来评估入侵检测系统对模仿攻击的安全性。我们展示了如何打破一个已发布的IDS的安全性与这些方法,我们实验确认模仿攻击的力量,给出一个具体的IDS实现的攻击的工作示例。最后,我们呼吁进一步研究入侵检测从攻击者和防御者的观点。
We examine several host-based anomaly detection systems and study their security against evasion attacks. First, we introduce the notion of a mimicry attack, which allows a sophisticated attacker to cloak their intrusion to avoid detection by the IDS. Then, we develop a theoretical framework for evaluating the security of an IDS against mimicry attacks. We show how to break the security of one published IDS with these methods, and we experimentally confirm the power of mimicry attacks by giving a worked example of an attack on a concrete IDS implementation. We conclude with a call for further research on intrusion detection from both attacker's and defender's viewpoints.