首页> 外文会议>International conference on cryptology and network security >iDeFEND: Intrusion Detection Framework for Encrypted Network Data
【24h】

iDeFEND: Intrusion Detection Framework for Encrypted Network Data

机译:IDEFEND:加密网络数据的入侵检测框架

获取原文

摘要

Network Intrusion Detection Systems have been used for many years to inspect network data and to detect intruders. Nowadays, more and more often encryption is used to protect the confidentiality of network data. When end-to-end encryption is applied, Network Intrusion Detection Systems are blind and can not protect against attacks. In this paper we present iDeFEND, a framework for inspecting encrypted network data without breaking the security model of end-to-end encryption. Our approach does not require any source code of the involved applications and thereby also protects closed source applications. Our framework works independently of the utilized encryption key. We present two use cases how our framework can detect intruders by analysing the network data and how we can test remote applications with enabled network data encryption. To achieve this iDeFEND detects the relevant functions in the target application, extracts and subsequently inspects the data. To test remote applications iDeFEND intercepts and injects user controlled data into the application to test remote applications. Finally we have implemented our framework to show the feasibility of our approach.
机译:网络入侵检测系统已被使用多年以检查网络数据并检测入侵者。如今,越来越多的加密用于保护网络数据的机密性。当应用端到端加密时,网络入侵检测系统是盲目的,无法防止攻击。在本文中,我们呈现了IDEFEND,该框架用于检查加密的网络数据,而不会破坏端到端加密的安全模型。我们的方法不需要涉及应用程序的任何源代码,从而保护闭合源应用程序。我们的框架独立于利用的加密密钥工作。我们展示了两种用例,我们的框架如何通过分析网络数据以及如何测试具有支持的网络数据加密的远程应用程序来检测入侵者。为实现此IDEFEND检测目标应用程序中的相关功能,提取并随后检查数据。要测试远程应用程序IDEFEND拦截并将用户受控数据注入应用程序以测试远程应用程序。最后,我们已经实施了我们的框架,以表明我们的方法的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号