ZDNet UK


Skip to Main Content

  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Videos
  6. Jobs
  7. Resources
  8. Community

 

ZDNet UK RSS Feeds


Security threats Toolkit

Download now

Network Intrusion Detection: Evasion, Traffic Normalization, and End-to-End Protocol Semantics

PublisherICIR (The ICSI Center for Internet Research)
Format HTMLDate added22 May 2001
Topics Anti-Hacking, Network Security
Downloads8

A fundamental problem for network intrusion detection systems is the ability of a skilled attacker to evade detection by exploiting ambiguities in the traffic stream as seen by the monitor. We discuss the viability of addressing this problem by introducing a new network forwarding element called a traffic normalizer. The normalizer sits directly in the path of traffic into a site and patches up the packet stream to eliminate potential ambiguities before the traffic is seen by the monitor, removing evasion opportunities. We examine a number of tradeoffs in designing a normalizer, emphasizing the important question of the degree to which normalizations undermine end-to-end protocol semantics. We discuss the key practical issues of "cold start" and attacks on the normalizer, and develop a methodology for systematically examining the ambiguities present in a protocol based on walking the protocol's header. We then present norm, a publicly available user-level implementation of a normalizer that can normalize a TCP traffic stream at 100,000 pkts/sec in memory-to-memory copies, suggesting that a kernel implementation using PC hardware could keep pace with a bidirectional 100 Mbps link with sufficient headroom to weather a high-speed flooding attack of small packets.

Download now

Did you find this white paper useful?
13 out of 37 users found this white paper useful


  • Trackback
  • Clip Link

Related white papers

Cyber Security Standards for the Power Industry

This webcast explains the basis of vulnerabilities in power companies' information systems, requirements imposed by the new NERC standards, and how to get started on compliance activities.


Navigate the new financial landscape

The landscape of the financial services industry is evolving, and financial institutions must adapt to the changing marketplace in order to succeed. This complimentary portfolio from IBM provides innovative thinking...


Risk, compliance and security: Can your financial institution weather the storm?

Learn how preemptive security can help stop Internet threats before they affect the network. IBM provides a variety of smart solutions tailored specifically for mid-sized financial institutions. Start with a...


Webcast: Homeland Security Industry Conference

In these difficult times, the task of protecting citizens is greater than ever, making homeland security a very large expenditure in President Bush's most recent budget plan. With overall spending...


Certification and Accreditation of Client Systems and Applications

A U.S. Navy organization responsible for development, deployment, and administration of logistics-related systems and applications required security engineering guidance and security Certification and Accreditation (C&A) support in accordance with Department...


Understanding California's Identity Theft Laws

While federal regulations calling for the protection of personal data in the digital age have garnered the vast majority of compliance-related news coverage in recent years, it's important to note...


MSDN Webcast: Remediation: Design Consideration for Architecting a Secure Web-Based Application (Level 200)

This webcast explains how to design systems that do not incorporate common architectural security defects and vulnerabilities. The webcast covers the major security risks affecting Web-based application architecture including session...


White Paper

Featured White Paper

Measuring the Pain: What is Fragmented Communications Costing Your Enterprise?

In this document, you will discover the results of the largest-ever survey of enterprise and contact center employees. Their workflows reveal the silent but staggering costs of fragmented communications. In fact enterprises with 1000 plus employees could be losing more than ?6 million a year.

Download Now

Other White Papers

High Level Best Practices in Software Configuration Management

When deploying new software configuration management (SCM) tools, implementers sometimes focus on...

Ten Things to Know About Grid Computing on Windows

This Oracle whitepaper offers insights into Oracle Grid. A grid allows a business to add capacity,...

See All White Papers