Multi-packet & multi-session signature detection using state based model

P. Pawar, M. Singh, S. Narayanan
{"title":"Multi-packet & multi-session signature detection using state based model","authors":"P. Pawar, M. Singh, S. Narayanan","doi":"10.1109/IADCC.2010.5423011","DOIUrl":null,"url":null,"abstract":"Signature Detection modules in IDS/IPS though accurate in pattern matching, yet it leads to false positives. This is due to the incompleteness of the signatures which lacks or has very little information about when, where and how to match these signatures. The signatures enriched with this information significantly brings down the false positives and at the same time enhances the performance of the signature detection module. In this paper we propose a state base signature detection model which leverages on our state aware signatures with sufficiently complete information to match these signatures. The proposed model keeps track of the state of the connection and matches the signatures within appropriate packets. We further classify our signatures that span across multiple packet and across multiple sessions. We also provide the notion of virtual signatures which represents patterns within packets in a distributed form. In this paper we demonstrate the capabilities of our proposed model to detect these virtual patterns, multi-packet and multi-session leveraging on our state aware signatures.","PeriodicalId":249763,"journal":{"name":"2010 IEEE 2nd International Advance Computing Conference (IACC)","volume":"61 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2010-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2010 IEEE 2nd International Advance Computing Conference (IACC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IADCC.2010.5423011","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Signature Detection modules in IDS/IPS though accurate in pattern matching, yet it leads to false positives. This is due to the incompleteness of the signatures which lacks or has very little information about when, where and how to match these signatures. The signatures enriched with this information significantly brings down the false positives and at the same time enhances the performance of the signature detection module. In this paper we propose a state base signature detection model which leverages on our state aware signatures with sufficiently complete information to match these signatures. The proposed model keeps track of the state of the connection and matches the signatures within appropriate packets. We further classify our signatures that span across multiple packet and across multiple sessions. We also provide the notion of virtual signatures which represents patterns within packets in a distributed form. In this paper we demonstrate the capabilities of our proposed model to detect these virtual patterns, multi-packet and multi-session leveraging on our state aware signatures.
基于状态模型的多包多会话签名检测
IDS/IPS中的签名检测模块虽然模式匹配准确,但会导致误报。这是由于签名的不完整性,缺少或只有很少关于何时、何地以及如何匹配这些签名的信息。包含这些信息的签名可以显著降低误报率,同时提高签名检测模块的性能。本文提出了一种基于状态的签名检测模型,该模型利用具有足够完整信息的状态感知签名来匹配这些签名。所建议的模型跟踪连接的状态,并在适当的数据包中匹配签名。我们进一步对跨越多个数据包和多个会话的签名进行分类。我们还提供了虚拟签名的概念,它以分布式形式表示数据包中的模式。在本文中,我们展示了我们提出的模型利用我们的状态感知签名来检测这些虚拟模式、多数据包和多会话的能力。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信