Attack Generation for NIDS Testing Using Natural Deduction

dc.contributor.authorRubin, Shaien_US
dc.contributor.authorJha, Someshen_US
dc.contributor.authorMiller, Barton P.en_US
dc.date.accessioned2012-03-15T17:17:49Z
dc.date.available2012-03-15T17:17:49Z
dc.date.created2004en_US
dc.date.issued2004
dc.description.abstractA common way to elude a signature-based NIDS is to transform an attack instance that the NIDS recognizes into another instance that it fails to recognize. For example, to avoid matching between the attack payload and the NIDS signature, attackers split the payload into several TCP packets, change it syntactically while preserving its semantics, or hide it between benign messages. We study attackers' ability to find attack instances that elude a NIDS and our ability to recognize such instances. We observe that different instances of a given attack can be derived from each other using simple transformations that change either the attack transport mechanism or its payload. We model these transformations as inference rules in a formal natural deduction system. Starting from an exemplary attack instance, we use an inference engine to automatically generate all possible instances derived from a particular collection of rules. The result is a simple yet powerful tool capable of both generating attack instances for NIDS testing and determining whether a given sequence of packets is an attack. During several testing phases using different sets of rules, our tool exposed serious vulnerabilities in Snort-a widely deployed NIDS. Attackers acquainted with these vulnerabilities would have been able to construct instances that elude Snort for any TCP-based attack, any Web-CGI attack, and any attack whose signature is a certain type of regular expression.en_US
dc.format.mimetypeapplication/pdfen_US
dc.identifier.citationTR1496en_US
dc.identifier.urihttp://digital.library.wisc.edu/1793/60380
dc.publisherUniversity of Wisconsin-Madison Department of Computer Sciencesen_US
dc.titleAttack Generation for NIDS Testing Using Natural Deductionen_US
dc.typeTechnical Reporten_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
TR1496.pdf
Size:
3.68 MB
Format:
Adobe Portable Document Format