DocumentCode
1628700
Title
Detection of network buffer overflow attacks: A case study
Author
Barabas, Maros ; Homoliak, Ivan ; Kacic, Matej ; Hanacek, Petr
Author_Institution
Fac. of Inf. Technol., Brno Univ. of Technol., Brno, Czech Republic
fYear
2013
Firstpage
1
Lastpage
4
Abstract
This paper presents an automated detection method based on classification of network traffic using predefined set of network metrics. We proposed the set of metrics with focus on behavior of buffer overflow attacks and their sufficient description without the need of deep packet inspection. In this paper we describe two laboratory experiments of automated detection of buffer overflow attacks on vulnerable network services and their description by proposed set of network metrics. We present the principles of several chosen network metrics and their application on experimental attacks according to their nature in comparison to valid communication.
Keywords
computer network security; pattern classification; attack detection; deep packet inspection; network buffer overflow attacks; network metrics; network traffic classification; Approximation methods; Indexes; Measurement; buffer overflow; detection; ids; network metrics;
fLanguage
English
Publisher
ieee
Conference_Titel
Security Technology (ICCST), 2013 47th International Carnahan Conference on
Conference_Location
Medellin
Type
conf
DOI
10.1109/CCST.2013.6922067
Filename
6922067
Link To Document