Title
Using Partial Signatures In Intrusion Detection For Multipath Tcp
Abstract
Traditional security mechanisms such as signature based intrusion detection systems (IDSs) attempt to find a perfect match of a set of signatures in network traffic. Such IDSs depend on the availability of a complete application data stream. With emerging protocols such as Multipath TCP (MPTCP), this precondition cannot be ensured, resulting in false negatives and IDS evasion. On the other hand, if approximate signature matching is used instead in an IDS, a potentially high number of false positives make the detection impractical. In this paper, we show that, by using a specially tailored partial signature matcher and knowledge about MPTCP semantics, the Snort3 IDS can be empowered with partial signature detection. Additionally, we uncover the type of Snort3 rules suitable for the task of partial matching. Experimental results with these rules show a low false positive rate for benign traffic and high detection coverage for attack traffic.
Year
DOI
Venue
2019
10.1007/978-3-030-35055-0_5
SECURE IT SYSTEMS, NORDSEC 2019
Field
DocType
Volume
Computer science,Multipath TCP,Computer network,Intrusion detection system
Conference
11875
ISSN
Citations 
PageRank 
0302-9743
0
0.34
References 
Authors
0
4
Name
Order
Citations
PageRank
Zeeshan Afzal111.07
Johan Garcia2111.57
Stefan Lindskog315321.77
Anna Brunström4113.73