Survey: Intrusion Detection Systems in Encrypted Traffic

Survey: Intrusion Detection Systems in Encrypted Traffic
复制标题

DOI:
10.1007/978-3-319-46301-8_23
复制
发表时间:
2016-09
期刊:
--
影响因子:
--
通讯作者:
T. Kovanen;G. David;T. Hämäläinen
T. Kovanen;G. David;T. Hämäläinen
中科院分区:
其他
文献类型:
--
作者:
T. Kovanen;G. David;T. Hämäläinen

文献摘要

被引文献

相似文献

入侵检测系统 IDS 传统上检查数据包的有效负载信息。此方法在加密流量中无效,因为有效负载信息不可用。有两种具有不同检测能力的方法可以克服加密的挑战:流量解密或流量分析。本文对加密流量中的 IDS 相关研究进行了全面的综述。重点是流量分析,不需要流量解密。接受调查的研究的主要局限性之一是,大多数研究都集中在检测相同的有限类型的攻击,例如暴力攻击或扫描攻击。讨论了使用 IDS 带来的安全增强以及加密流量带来的安全挑战。通过对现有工作进行分类,提出了一系列结论和对未来研究方向的建议。
Intrusion detection system, IDS, traditionally inspects the payload information of packets. This approach is not valid in encrypted traffic as the payload information is not available. There are two approaches, with different detection capabilities, to overcome the challenges of encryption: traffic decryption or traffic analysis. This paper presents a comprehensive survey of the research related to the IDSs in encrypted traffic. The focus is on traffic analysis, which does not need traffic decryption. One of the major limitations of the surveyed researches is that most of them are concentrating in detecting the same limited type of attacks, such as brute force or scanning attacks. Both the security enhancements to be derived from using the IDS and the security challenges introduced by the encrypted traffic are discussed. By categorizing the existing work, a set of conclusions and proposals for future research directions are presented.