• DocumentCode
    1628700
  • Title

    Detection of network buffer overflow attacks: A case study

  • Author

    Barabas, Maros ; Homoliak, Ivan ; Kacic, Matej ; Hanacek, Petr

  • Author_Institution
    Fac. of Inf. Technol., Brno Univ. of Technol., Brno, Czech Republic
  • fYear
    2013
  • Firstpage
    1
  • Lastpage
    4
  • Abstract
    This paper presents an automated detection method based on classification of network traffic using predefined set of network metrics. We proposed the set of metrics with focus on behavior of buffer overflow attacks and their sufficient description without the need of deep packet inspection. In this paper we describe two laboratory experiments of automated detection of buffer overflow attacks on vulnerable network services and their description by proposed set of network metrics. We present the principles of several chosen network metrics and their application on experimental attacks according to their nature in comparison to valid communication.
  • Keywords
    computer network security; pattern classification; attack detection; deep packet inspection; network buffer overflow attacks; network metrics; network traffic classification; Approximation methods; Indexes; Measurement; buffer overflow; detection; ids; network metrics;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security Technology (ICCST), 2013 47th International Carnahan Conference on
  • Conference_Location
    Medellin
  • Type

    conf

  • DOI
    10.1109/CCST.2013.6922067
  • Filename
    6922067