首页> 外文期刊>Evolutionary Intelligence >Evolutionary computation as an artificial attacker: generating evasion attacks for detector vulnerability testing
【24h】

Evolutionary computation as an artificial attacker: generating evasion attacks for detector vulnerability testing

机译:作为人为攻击者的进化计算:生成逃避攻击以进行检测器漏洞测试

获取原文
获取原文并翻译 | 示例
       

摘要

Intrusion detection systems protect our infrastructures by monitoring for signs of intrusions. However, intrusion detection systems are themselves susceptible to vulnerabilities, which the attackers take advantage of to evade detection. In particular, we focus on evasion attacks in which the attacker aims to generate a stealthy attack that eliminates or minimizes the likelihood of detection. Attackers achieve stealth by mimicking normal behaviour while achieving the attack goals, hence bypassing the detector. Previous work focused on generating evasion attacks using the internal knowledge of the detectors, hence adopting a ‘white-box’ access to the detector. On the other hand, we adopt a ‘black-box’ approach and propose an evolutionary attacker based on Genetic Programming. The access of our ‘black-box’ approach is limited to the feedback of the detector such as anomaly rates and delays. We compare our ‘black-box’ approach with various ‘white-box’ approaches to investigate its effectiveness. In doing so, the impact of anomalies from the break-in stage of the attacks and the delays based on locality frame counts are also discussed. This is particularly important if the performance comparison is to reflect the real capabilities of detectors.
机译:入侵检测系统通过监视入侵迹象来保护我们的基础架构。但是,入侵检测系统本身容易受到漏洞的攻击,攻击者利用这些漏洞逃避了检测。特别是,我们专注于规避攻击,在这种规避攻击中,攻击者旨在产生一种隐匿性攻击,该攻击可消除或最小化检测到的可能性。攻击者在实现攻击目标的同时模仿正常行为来实现隐身,从而绕过检测器。先前的工作着重于利用检测器的内部知识来产生逃避攻击,因此采用了对检测器的“白盒”访问方式。另一方面,我们采用“黑匣子”方法,并提出了一种基于遗传编程的进化攻击者。我们“黑匣子”方法的访问仅限于检测器的反馈,例如异常率和延迟。我们将“黑盒”方法与各种“白盒”方法进行了比较,以研究其有效性。在此过程中,还讨论了攻击进入阶段的异常影响以及基于局部帧计数的延迟。如果性能比较要反映检测器的实际功能,则这尤其重要。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号