Advertisement
Promo

Security management Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Download now

An Achilles' Heel in Signature-Based IDS: Squealing False Positives in SNORT

PublisherIllinois State University
Format31.0KB PDFDate added11 Aug 2001
Topics Digital Signatures, Security Tools, Intrusion Detection Systems
Downloads78

This paper reports a vulnerability to network signature-based IDS which has been tested using Snort and is called "Squealing". This vulnerability has significant implications since it can easily be generalized to any IDS. The vulnerability of signature-based IDS to high false positive rates has been well-documented but one goes further to show (at a high level) how packets can be crafted to match attack signatures such that a alarms on a target IDS can be conditioned or disabled and then exploited. This is the first academic treatment of this vulnerability that has already been reported to the CERT Coordination Center and the National Infrastructure Protection Center. Independently, other tools based on "Squealing" are poised to appear that, while validating our ideas, also gives cause for concern.

Download now

Did you find this white paper useful?
1 out of 3 users found this white paper useful


  • Trackback
  • Clip Link

Related white papers

Efficient Byzantine Broadcast in Wireless Ad-Hoc Networks

This paper presents an overlay based Byzantine tolerant broadcast protocol for wireless ad-hoc networks. The use of an overlay results in a significant reduction in the number of messages. The...


Delivering Intelligent Network Access through Identity-Driven Management

Download this ProCurve Networking white paper from HP to read up on identity-driven management (IDM), a next-generation approach to access control that significantly improves network security. The paper explains how...


Extended Validation SSL Digital Certificate Research Study

Late in 2006, the industry standards body called the CA/Browser Forum released its specification for a new class of SSL Certificate called an Extended Validation (EV) SSL Certificate. Because these...


Technical Brief: Identity-Driven Management

This white paper introduces ProCurve Identity Driven Manager 2.0 (IDM 2.0), a next-generation solution from HP that enables companies to dramatically improve information security, network resiliency, and overall business efficiency....


The Value of Authentication: Authentication + Encryption + Certification Authority = Trust

One of the biggest problems facing your Internet business today is the thorny issue of trust and security. People simply don't trust the Web, fearing that their transactions might not...


Trusted Computing – Getting Started In Three Easy Steps

It is a reality in today’s business environment that enterprise and government data is vulnerable to attack. Critical incidents are reported by the media daily including identity theft, information leakage,...


Trusted Computing: Trusted Platform Management and Key Recovery

The computer industry offers a variety of PCs and desktop boards equipped with a Trusted Computing Module (TPM), a dedicated microchip enabled for security capabilities. Specifications for the TPM have...


White Paper

Featured White Paper

Selecting a Microsoft Hosted Exchange Service Provider

When it comes to the decision to outsource the delivery of your organisation's messaging solution, the task of selecting the most appropriate service provider can be daunting This whitepaper from Cobweb Solutions, Europe's leading Microsoft Hosted Exchange provider, is designed to help simplify that task for you, by arming you with the important ...

Download Now

Other White Papers

Business Efficiency in Unprecedented Times

In these unprecedented times, organisations are left with no choice but to seek out more and more...

Desktop Virtualization on IBM BladeCenter and System x Servers: Taking Back Control of the Desktop

"Operational efficiency is imperative in today's competitive marketplace. Thus, the IT strategies...

See All White Papers

Video icon

Video


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters