DocumentCode :
1629307
Title :
Multi-packet & multi-session signature detection using state based model
Author :
Pawar, Pramod S. ; Singh, Mayank Pal ; Narayanan, Sachin
Author_Institution :
Comput. Network & Internet Eng.(CNIE), Center For Dev. Of Ad v. Comput.(CDAC), Bangalore, India
fYear :
2010
Firstpage :
190
Lastpage :
194
Abstract :
Signature Detection modules in IDS/IPS though accurate in pattern matching, yet it leads to false positives. This is due to the incompleteness of the signatures which lacks or has very little information about when, where and how to match these signatures. The signatures enriched with this information significantly brings down the false positives and at the same time enhances the performance of the signature detection module. In this paper we propose a state base signature detection model which leverages on our state aware signatures with sufficiently complete information to match these signatures. The proposed model keeps track of the state of the connection and matches the signatures within appropriate packets. We further classify our signatures that span across multiple packet and across multiple sessions. We also provide the notion of virtual signatures which represents patterns within packets in a distributed form. In this paper we demonstrate the capabilities of our proposed model to detect these virtual patterns, multi-packet and multi-session leveraging on our state aware signatures.
Keywords :
digital signatures; pattern matching; IDS; IPS; multipacket signature detection; multisession signature detection; pattern matching; state aware signatures; state base model; Change detection algorithms; Computer networks; Computer vision; IP networks; Intrusion detection; Pattern matching; Protocols; Search engines; Telecommunication traffic; Multi-Packet; Multi-Session; State Based Model; State Based Signature; component;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advance Computing Conference (IACC), 2010 IEEE 2nd International
Conference_Location :
Patiala
Print_ISBN :
978-1-4244-4790-9
Electronic_ISBN :
978-1-4244-4791-6
Type :
conf
DOI :
10.1109/IADCC.2010.5423011
Filename :
5423011
Link To Document :
بازگشت