首页> 外文OA文献 >An approach towards anomaly based detection and profiling covert TCP/IP channels
【2h】

An approach towards anomaly based detection and profiling covert TCP/IP channels

机译:一种基于异常的检测和配置隐蔽TCP / IP通道的方法

摘要

Firewalls and detection systems have been used for preventing and detecting attacks by a wide variety of mechanisms. A problem has arisen where users and applications can circumvent security policies because of the particularities in the TCP/IP protocol, the ability to obfuscate the data payload, tunnel protocols, and covertly simulate a permitted communication. It has been shown that unusual traffic patterns may lead to discovery of covert channels that employ packet headers. In addition, covert channels can be detected by observing an anomaly in unused packet header fields. Presently, we are not aware of any schemes that address detecting anomalous traffic patterns that can potentially be created by a covert channel. In this work, we will explore the approach of combining anomaly based detection and covert channel profiling to be used for detecting a very precise subset of covert storage channels in network protocols. We shall also discuss why this method is more practical and industry-ready compared to the present research on how to profile and mitigate these types of attacks. Finally, we shall describe a specialized tool to passively monitor networks for these types of attacks and show how it can be used to build an efficient hybrid covert channel and anomaly based detection system.
机译:防火墙和检测系统已通过多种机制用于预防和检测攻击。由于TCP / IP协议的特殊性,混淆数据有效负载,隧道协议并秘密模拟允许的通信的能力,用户和应用程序可能会规避安全策略。已经表明,异常的业务量模式可能导致发现采用分组报头的隐蔽信道。另外,可以通过观察未使用的分组报头字段中的异常来检测隐蔽信道。目前,我们还不知道有任何方案可以解决检测隐蔽通道可能产生的异常流量模式的问题。在这项工作中,我们将探索将基于异常的检测和隐蔽通道分析相结合的方法,以用于检测网络协议中隐蔽存储通道的非常精确的子集。与目前有关如何分析和缓解这些类型的攻击的研究相比,我们还将讨论为什么这种方法更实用,更易于工业应用。最后,我们将描述一种专用工具,用于被动监视网络中的这些类型的攻击,并说明如何将其用于构建有效的混合秘密通道和基于异常的检测系统。

著录项

  • 作者

    Gilbert Patrick A;

  • 作者单位
  • 年度 2009
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号