Application Level IDS using Protocol Analysis

K. Rajkumar, V. Vaidehi, S. Pradeep, N. Srinivasan, M. Vanishree
{"title":"Application Level IDS using Protocol Analysis","authors":"K. Rajkumar, V. Vaidehi, S. Pradeep, N. Srinivasan, M. Vanishree","doi":"10.1109/ICSCN.2007.350762","DOIUrl":null,"url":null,"abstract":"As network attacks have increased in number and severity over the past few years, intrusion detection systems have become a necessary addition to the security infrastructure of most organizations. From a security perspective, firewalls and SSL offer little protection. Web traffic often contains attacks such as cross-site scripting and SQL injection that enter through port 80 and are not blocked by the firewall. Among the Web applications HTTP holds the majority share of the traffic transported through Web. In this paper, implementation of an application level IDS has been presented which uses combination of pattern matching and protocol analysis approaches. The first method of detection relies on a multi pattern matching within the protocol fields, the second one provides an efficient decision tree adaptive to the application traffic characteristics to limit the number of patterns to be checked. The proposed IDS can be effectively implemented in a high performance semantic processor","PeriodicalId":257948,"journal":{"name":"2007 International Conference on Signal Processing, Communications and Networking","volume":"64 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-11-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 International Conference on Signal Processing, Communications and Networking","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSCN.2007.350762","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

As network attacks have increased in number and severity over the past few years, intrusion detection systems have become a necessary addition to the security infrastructure of most organizations. From a security perspective, firewalls and SSL offer little protection. Web traffic often contains attacks such as cross-site scripting and SQL injection that enter through port 80 and are not blocked by the firewall. Among the Web applications HTTP holds the majority share of the traffic transported through Web. In this paper, implementation of an application level IDS has been presented which uses combination of pattern matching and protocol analysis approaches. The first method of detection relies on a multi pattern matching within the protocol fields, the second one provides an efficient decision tree adaptive to the application traffic characteristics to limit the number of patterns to be checked. The proposed IDS can be effectively implemented in a high performance semantic processor
使用协议分析的应用层IDS
在过去的几年中,随着网络攻击的数量和严重程度的增加,入侵检测系统已经成为大多数组织安全基础设施的必要补充。从安全角度来看,防火墙和SSL提供的保护很少。Web流量通常包含跨站点脚本和SQL注入等攻击,这些攻击通过端口80进入,不会被防火墙阻止。在Web应用程序中,HTTP占有通过Web传输的流量的大部分份额。本文提出了一种结合模式匹配和协议分析方法的应用层入侵检测系统的实现方法。第一种检测方法依赖于协议字段内的多模式匹配,第二种检测方法提供了一种适应应用程序流量特征的有效决策树,以限制要检查的模式数量。所提出的IDS可以在高性能语义处理器中有效实现
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信