【24h】

Evolving TCP/IP packets: A case study of port scans

机译:不断发展的TCP / IP数据包:端口扫描的案例研究

获取原文

摘要

In this work, we investigate the ability of genetic programming techniques to evolve valid network packets, including all relevant header values, towards a specific goal. We see this as a first step in building a fuzzing system that can learn to adapt for vulnerability analysis. By developing a system that learns the packets that are required to be transmitted towards targets, using feedback from an external network source, we make a step towards having a system that can intelligently explore the capabilities of a given security system. In order to validate our system's capabilities we evolve a variety of port scan patterns while running the packets through an IDS, with the goal to minimizes the alarms raised during the scanning process. Results show that the system not only successfully evolves valid TCP packets, but also remains stealthy in its activity.
机译:在这项工作中,我们调查了遗传编程技术向特定目标发展有效网络数据包(包括所有相关标头值)的能力。我们认为这是构建可学习适应漏洞分析的模糊测试系统的第一步。通过使用来自外部网络源的反馈,开发一个学习需要向目标发送的数据包的系统,我们朝着拥有可以智能地探索给定安全系统功能的系统迈出了一步。为了验证我们系统的功能,我们在通过IDS运行数据包的同时改进了各种端口扫描模式,目的是最大程度地减少在扫描过程中发出的警报。结果表明,该系统不仅成功地演化了有效的TCP数据包,而且在其活动中仍然保持隐身状态。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号