DocumentCode :
3040710
Title :
Tuning Intrusion Detection to Work with a Two Encryption Key Version of IPsec
Author :
Studer, Ahren ; McLain, Cynthia ; Lippmann, Richard
Author_Institution :
MIT Lincoln Laboratory, Lexington, MA; Carnegie Mellon University, Pittsburgh, PA
fYear :
2007
fDate :
29-31 Oct. 2007
Firstpage :
1
Lastpage :
7
Abstract :
Network-based intrusion detection systems (NIDSs) are one component of a comprehensive network security solution. The use of IPsec, which encrypts network traffic, renders network intrusion detection virtually useless unless traffic is decrypted at network gateways. Host-based intrusion detection systems (HIDSs) can provide some of the functionality of NIDSs but with limitations. HIDSs cannot perform a network-wide analysis and can be subverted if a host is compromised. We propose an approach to intrusion detection that combines HIDS, NIDS, and a version of IPsec that encrypts the header and the body of IP packets separately ("Two-Zone IPsec"). We show that all of the network events currently detectable by the Snort NIDS on unencrypted network traffic are also detectable on encrypted network traffic using this approach. The NIDS detects network-level events that HIDSs have trouble detecting and HIDSs detect application-level events that can\´t be detected by the NIDS.
Keywords :
Cryptography; Electrostatic precipitators; Event detection; Intrusion detection; Laboratories; Pattern matching; Payloads; Performance analysis; Protocols; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Military Communications Conference, 2007. MILCOM 2007. IEEE
Conference_Location :
Orlando, FL, USA
Print_ISBN :
978-1-4244-1513-7
Electronic_ISBN :
978-1-4244-1513-7
Type :
conf
DOI :
10.1109/MILCOM.2007.4455095
Filename :
4455095
Link To Document :
بازگشت