• DocumentCode
    1600947
  • Title

    Efficient and Robust TCP Stream Normalization

  • Author

    Vutukuru, Mythili ; Balakrishnan, Hari ; Paxson, Vern

  • Author_Institution
    MIT CSAIL, Cambridge, MA
  • fYear
    2008
  • Firstpage
    96
  • Lastpage
    110
  • Abstract
    Network intrusion detection and prevention systems are vulnerable to evasion by attackers who craft ambiguous traffic to breach the defense of such systems. A normalizer is an inline network element that thwarts evasion attempts by removing ambiguities in network traffic. A particularly challenging step in normalization is the sound detection of inconsistent TCP retransmissions, wherein an attacker sends TCP segments with different payloads for the same sequence number space to present a network monitor with ambiguous analysis. Normalizers that buffer all unacknowledged data to verify the consistency of subsequent retransmissions consume inordinate amounts of memory on highspeed links. On the other hand, normalizers that buffer only the hashes of unacknowledged segments cannot verify the consistency of 20-30% of retransmissions that, according to our traces, do not align with the original transmissions. This paper presents the design of RoboNorm, a normalizer that buffers only the hashes of unacknowledged segments, and yet can detect all inconsistent retransmissions in any TCP byte stream. RoboNorm consumes 1-2 orders of magnitude less memory than normalizers that buffers all unacknowledged data, and is amenable to a high-speed implementation. RoboNorm is also robust to attacks that attempt to compromise its operation or exhaust its resources.
  • Keywords
    security of data; telecommunication security; transport protocols; RoboNorm; TCP byte stream; Transmission Control Protocol; hash; network intrusion detection; normalizer; robust TCP stream normalization; Buffer storage; IP networks; Intrusion detection; Monitoring; Payloads; Privacy; Protection; Robustness; TCPIP; Telecommunication traffic; Evasion Attacks; Intrusion Detection Systems; Normalization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2008. SP 2008. IEEE Symposium on
  • Conference_Location
    Oakland, CA
  • ISSN
    1081-6011
  • Print_ISBN
    978-0-7695-3168-7
  • Type

    conf

  • DOI
    10.1109/SP.2008.27
  • Filename
    4531147