Dropped here by your search engine? Use the same keyword in the google box below to search this site.
Google
 
Web This Site


Network Intrusion Detection Signatures, Part Five

This is the fifth and final installment in a series of articles on understanding and developing signatures for network intrusion detection systems. In the previous article, we looked at the topic of protocol analysis, meaning that the intrusion detection system actually understands how various protocols, such as FTP, are supposed to work. We initially looked at protocol analysis as it applied to a single request or response. In this article, we will extend this discussion by looking closely at stateful protocol analysis, which involves performing protocol analysis for an entire connection or session, capturing and storing certain pieces of relevant data seen in the session, and using that data to identify attacks that involve multiple requests and responses.

Stateful Protocol Analysis

The concept of stateful protocol analysis is simple: to add stateful characteristics to regular protocol analysis. When we perform protocol analysis, we examine TCP and UDP payloads, which contain protocols such as DNS, FTP, HTTP and SMTP. IDS sensors that perform protocol analysis understand how each protocol is supposed to work, based on RFCs and on real-world implementations of these protocols. So the IDS sensor can detect many suspicious values within protocol application payloads. Protocol analysis signatures can also be designed to overcome attempts by attackers to obfuscate their exploits. For example, hex encoding can be used to slightly modify URLs so that they appear different to us but have the same meaning to Web servers. Microsoft IIS Web servers perform two hex decoding operations on URLs before processing them: an HTTP protocol analysis signature set looking for IIS attempts should also perform two hex decoding operations, so that it is examining the same URL that the IIS Web server would see. Network Intrusion Detection Signatures, Part Five



More News



You are browsing the old version of "The Network Security. Org", Please
click here to visit the
new version.


Categories


RSS feed



server uptime monitor service




Warning: main(ad_network_213.php) [function.main]: failed to open stream: No such file or directory in /home/thenetw/public_html/news/View.php on line 282

Warning: main(ad_network_213.php) [function.main]: failed to open stream: No such file or directory in /home/thenetw/public_html/news/View.php on line 282

Warning: main(ad_network_213.php) [function.main]: failed to open stream: No such file or directory in /home/thenetw/public_html/news/View.php on line 282

Warning: main() [function.include]: Failed opening 'ad_network_213.php' for inclusion (include_path='.:/usr/lib/php:/usr/local/lib/php:../:../../:../../../:../../../../') in /home/thenetw/public_html/news/View.php on line 282