Abstract | ||
---|---|---|
Traditional security mechanisms such as signature based intrusion detection systems (IDSs) attempt to find a perfect match of a set of signatures in network traffic. Such IDSs depend on the availability of a complete application data stream. With emerging protocols such as Multipath TCP (MPTCP), this precondition cannot be ensured, resulting in false negatives and IDS evasion. On the other hand, if approximate signature matching is used instead in an IDS, a potentially high number of false positives make the detection impractical. In this paper, we show that, by using a specially tailored partial signature matcher and knowledge about MPTCP semantics, the Snort3 IDS can be empowered with partial signature detection. Additionally, we uncover the type of Snort3 rules suitable for the task of partial matching. Experimental results with these rules show a low false positive rate for benign traffic and high detection coverage for attack traffic. |
Year | DOI | Venue |
---|---|---|
2019 | 10.1007/978-3-030-35055-0_5 | SECURE IT SYSTEMS, NORDSEC 2019 |
Field | DocType | Volume |
Computer science,Multipath TCP,Computer network,Intrusion detection system | Conference | 11875 |
ISSN | Citations | PageRank |
0302-9743 | 0 | 0.34 |
References | Authors | |
0 | 4 |
Name | Order | Citations | PageRank |
---|---|---|---|
Zeeshan Afzal | 1 | 1 | 1.07 |
Johan Garcia | 2 | 11 | 1.57 |
Stefan Lindskog | 3 | 153 | 21.77 |
Anna Brunström | 4 | 11 | 3.73 |