Survey: Intrusion Detection Systems in Encrypted Traffic
Survey: Intrusion Detection Systems in Encrypted Traffic
复制标题
DOI:
10.1007/978-3-319-46301-8_23
复制
发表时间:
2016-09
期刊:
影响因子:
--
通讯作者:
T. Kovanen;G. David;T. Hämäläinen
中科院分区:
文献类型:
--
作者:
T. Kovanen;G. David;T. Hämäläinen
Intrusion detection system, IDS, traditionally inspects the payload information of packets. This approach is not valid in encrypted traffic as the payload information is not available. There are two approaches, with different detection capabilities, to overcome the challenges of encryption: traffic decryption or traffic analysis. This paper presents a comprehensive survey of the research related to the IDSs in encrypted traffic. The focus is on traffic analysis, which does not need traffic decryption. One of the major limitations of the surveyed researches is that most of them are concentrating in detecting the same limited type of attacks, such as brute force or scanning attacks. Both the security enhancements to be derived from using the IDS and the security challenges introduced by the encrypted traffic are discussed. By categorizing the existing work, a set of conclusions and proposals for future research directions are presented.