• DocumentCode
    1840220
  • Title

    Transport and application protocol scrubbing

  • Author

    Malan, G. Robert ; Watson, David ; Jahanian, Famm ; Howell, Paul

  • Author_Institution
    Dept. of Electr. Eng. & Comput. Sci., Michigan Univ., Ann Arbor, MI, USA
  • Volume
    3
  • fYear
    2000
  • fDate
    26-30 Mar 2000
  • Firstpage
    1381
  • Abstract
    This paper describes the design and implementation of a protocol scrubber, a transparent interposition mechanism for explicitly removing network attacks at both the transport and application protocol layers. The transport scrubber supports downstream passive network-based intrusion detection systems; whereas the application scrubbing mechanism supports transparent fail-closed active network-based intrusion detection systems. The transport scrubber´s role is to convert ambiguous network flows into well-behaved flows that are unequivocally interpreted by all downstream endpoints. As an example, this paper presents the implementation of a TCP/IP scrubber that eliminates insertion and evasion attacks-attacks that use ambiguities to subvert detection-on passive network-based intrusion detection systems, while preserving high performance. The application protocol scrubbing mechanism is used as a substrate for building fail-closed active network based intrusion detections systems that can respond to attacks by eluding or modifying application data flows in real-time. This paper presents the high performance implementation of a general purpose transparent application-level scrubbing toolkit in the FreeBSD kernel
  • Keywords
    Internet; protocols; security of data; software tools; telecommunication computing; telecommunication security; transport protocols; FreeBSD kernel; Internet; TCP/IP scrubber; ambiguous network flows; application protocol scrubbing; downstream endpoints; downstream passive network-based intrusion detection; evasion attacks; insertion attacks; network attacks; protocol layers; transparent application-level scrubbing toolkit; transparent fail-closed active network-based intrusion detection; transparent interposition mechanism; transport protocol scrubbing; Application software; Banking; Business; Intrusion detection; Kernel; Mission critical systems; Monitoring; Pattern recognition; Real time systems; Transport protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2000. Nineteenth Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings. IEEE
  • Conference_Location
    Tel Aviv
  • ISSN
    0743-166X
  • Print_ISBN
    0-7803-5880-5
  • Type

    conf

  • DOI
    10.1109/INFCOM.2000.832535
  • Filename
    832535