Title :
Classification and Discovery of Rule Misconfigurations in Intrusion Detection and Response Devices
Author :
Stakhanova, Natalia ; Li, Yao ; Ghorbani, Ali A.
Author_Institution :
Fac. of Comput. Sci., Univ. of New Brunswick, Fredericton, NB, Canada
Abstract :
The signature-based intrusion detection is one of the most commonly used techniques implemented in modern intrusion detection systems (IDS). Being based on a set of rules, i.e., attack signatures, the accuracy and reliability of IDS detection heavily depend on the quality of the employed rule set. In this context, any conflicts that arise between rules create ambiguity in classification of network traffic or host events, not only affecting the performance of IDS, but also putting the system in a vulnerable position. Currently existing techniques for conflict detection focus primarily on the security policy of the network devices: IPSec, routers, firewalls. In this paper we address the conflict detection in host and network-based intrusion detection and response devices and present a rule management framework that allows rule set analysis for potential conflicts. We demonstrate the advantages of the proposed approach on three collections of attack signatures: the set provided by the vendor of the commercial IDS and the rule sets of the open source Snort IDS and bleeding edge threats. Our analysis reveal conflicts in each of them.
Keywords :
knowledge based systems; security of data; bleeding edge threat; conflict detection; open source Snort IDS; rule management framework; rule misconfiguration classification; rule misconfiguration discovery; signature-based intrusion detection; Computer network reliability; Computer science; Computer security; Event detection; Hemorrhaging; Intrusion detection; Niobium; Payloads; Privacy; Telecommunication traffic; attack signitures; intrusion detection;
Conference_Titel :
Privacy, Security, Trust and the Management of e-Business, 2009. CONGRESS '09. World Congress on
Conference_Location :
Saint John, NB
Print_ISBN :
978-1-4244-5344-3
Electronic_ISBN :
978-0-7695-3805-1
DOI :
10.1109/CONGRESS.2009.12