ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Mobile working Toolkit

Download now

Network Intrusion Detection: Evasion, Traffic Normalization, and End-to-End Protocol Semantics

Did you find this white paper useful?


Publisher Technische Universitat Munchen
Publisher Registration N/A
Topics Network Security, Security Tools, Intrusion Detection Systems Date added 22 May 2001
Downloads 15 Format 554.2KB PDF

A fundamental problem for network intrusion detection systems is the ability of a skilled attacker to evade detection by exploiting ambiguities in the traffic stream as seen by the monitor. This paper discusses the viability of addressing this problem by introducing a new network forwarding element called a traffic normalizer. The normalizer sits directly in the path of traffic into a site and patches up the packet stream to eliminate potential ambiguities before the traffic is seen by the monitor, removing evasion opportunities. The paper examines a number of tradeoffs in designing a normalizer, emphasizing the important question of the degree to which normalizations undermine end-to-end protocol semantics.

Download now

Did you find this white paper useful?


  • Trackback
  • Clip Link

Related white papers

Balancing Security Against Productivity

What makes for great security? Is it about keeping the bad guys out or letting the good guys in? About defending attacks or preventing them? When IDG Research Services queried...


Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Still super gluing your USB ports shut? Unauthorized access to networks, lost or stolen laptops and other mobile hardware, and theft of proprietary information or intellectual property accounted for more...


Secure Desktop On-Demand Webcast

The desktop or endpoint is one of the most vulnerable parts of your environment. Threats are everywhere. You have users who love to experiment with device settings (only to wonder...


Commercial Leasing Company Increases Security With Desktop Operating System Solution

Signature Capital provides customized vehicle and equipment financing packages to meet the specific financial needs of its clients. As a small startup company, Signature Capital was lacking the resources it...


Stop Spam and Email-Borne Threats With Symantec's New Hosted Mail Security Solution

Organizations of all sizes are coping with threats to business productivity and security from spam, viruses and worms, and other email-borne content. To combat these attacks, Symantec provides industry-leading email...


Small Business Webcast: Upgrade Today: An Overview of Windows XP Service Pack 2 - Level 100

Did you know that the Windows XP Service Pack 2 has a number of security enhancements to help you protect your PC? In this webcast, you will find out more...


Securing SMBs Against Spam and Virus Threats

This white paper from St. Bernard Software explains why spam and viruses are particularly tough to eliminate in small- and medium-sized businesses (SMBs) that can't dedicate IT staff to combating...


White Paper

Featured White Paper

11 things to consider for File Virtualization

As organizations struggle to cope with the exponential growth of data, especially in the unstructured and decentralized file space, the urgency to gain better control, visibility and transparency of file data also grows.

Download Now

Other White Papers

Inter-site Ethernet: A guide to choosing your Ethernet service provider

The market for Ethernet is continuing to grow, as UK organisations appreciate the cost savings,...

Laying the foundations for evolving eGovernment: Why next generation Ethernet technology holds the key

The UK Government has committed to transform the public sector by making truly e-enabled...

See All White Papers