首页> 外文会议>IEEE International Workshop on Computer Aided Modeling and Design of Communication Links and Networks >Head(er)Hunter: Fast Intrusion Detection using Packet Metadata Signatures
【24h】

Head(er)Hunter: Fast Intrusion Detection using Packet Metadata Signatures

机译:Head(er)Hunter:使用数据包元数据签名的快速入侵检测

获取原文

摘要

More than 75% of the Internet traffic is now encrypted, while this percentage is constantly increasing. The majority of communications are secured using common encryption protocols such as SSL/TLS and IPsec to ensure security and protect the privacy of Internet users. Yet, encryption can be exploited to hide malicious activities. Traditionally, network traffic inspection is based on techniques like deep packet inspection (DPI). Common applications for DPI include but are not limited to firewalls, intrusion detection and prevention systems, L7 filtering and packet forwarding. The core functionality of such DPI implementations is based on pattern matching that enables searching for specific strings or regular expressions inside the packet contents. With the widespread adoption of network encryption though, DPI tools that rely on packet payload content are becoming less effective, demanding the development of more sophisticated techniques in order to adapt to current network encryption trends. In this work, we present HeaderHunter, a fast signature-based intrusion detection system even in encrypted network traffic. We generate signatures using only network packet metadata extracted from packet headers. Also, to cope with the ever increasing network speeds, we accelerate the inner computations of our proposed system using off-the-shelf GPUs.
机译:现在,超过75%的Internet流量已被加密,而这一百分比正在不断增加。大多数通信使用SSL / TLS和IPsec等通用加密协议来保护,以确保安全性并保护Internet用户的隐私。但是,可以利用加密来隐藏恶意活动。传统上,网络流量检查基于深度数据包检查(DPI)之类的技术。 DPI的常见应用程序包括但不限于防火墙,入侵检测和防御系统,L7过滤和数据包转发。这种DPI实现的核心功能基于模式匹配,该模式匹配可在数据包内容内搜索特定的字符串或正则表达式。但是,随着网络加密的广泛采用,依赖于数据包有效载荷内容的DPI工具的有效性越来越低,需要开发更复杂的技术来适应当前的网络加密趋势。在这项工作中,我们介绍了HeaderHunter,这是一种即使在加密的网络流量中,也基于签名的快速入侵检测系统。我们仅使用从数据包标头中提取的网络数据包元数据生成签名。此外,为了应对不断增长的网络速度,我们使用现成的GPU加速了我们提出的系统的内部计算。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号