• DocumentCode
    3108026
  • Title

    Language-based generation and evaluation of NIDS signatures

  • Author

    Rubin, Shai ; Jha, Somesh ; Miller, Barton P.

  • Author_Institution
    Dept. of Comput. Sci., Wisconsin Univ., Madison, WI, USA
  • fYear
    2005
  • fDate
    8-11 May 2005
  • Firstpage
    3
  • Lastpage
    17
  • Abstract
    We present a methodology to automatically construct robust signatures whose accuracy is based on formal reasoning so it can be systematically evaluated. Our methodology is based on two formal languages that describe different properties of a given attack. The first language, called a session signature, describes temporal relations between the attack events. The second, called an attack invariant, describes semantic properties that hold in any instance of the attack. For example, an invariant may state that a given FTP attack must include a successful FTP login and can be launched only after the FTP representation mode has been set to ASCII. We iteratively eliminate false positives and negatives from an initial session signature by comparing the signature language to the language of the invariant. We developed GARD, a tool for session-signature construction, and used it to construct session signatures for multi-step attacks. We show that a session signature is more accurate than existing signatures.
  • Keywords
    computer network management; digital signatures; formal languages; programming language semantics; security of data; FTP attack; GARD; NIDS signature evaluation; attack invariant; formal languages; formal reasoning; language-based generation; multi-step attacks; network intrusion detection system; robust signatures; semantic properties; session-signature construction; temporal relations; Bridges; Formal languages; Intrusion detection; Pattern matching; Performance analysis; Performance evaluation; Privacy; Protocols; Robustness; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2005 IEEE Symposium on
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-2339-0
  • Type

    conf

  • DOI
    10.1109/SP.2005.10
  • Filename
    1425055