DocumentCode :
1756214
Title :
Behavior-based intrusion detection in encrypted environments
Author :
Koch, Robert ; Golling, M. ; Rodosek, Gabi Dreo
Author_Institution :
Univ. der Bundeswehr Munchen, Neubiberg, Germany
Volume :
52
Issue :
7
fYear :
2014
fDate :
41821
Firstpage :
124
Lastpage :
131
Abstract :
In recent years the Internet has evolved into a critical communication infrastructure that is omnipresent in almost all aspects of our daily life. This dependence of modern societies on the Internet has also resulted in more criminals using the Internet for their purposes, causing a steady increase of attacks, both in terms of quantity as well as quality. Although research on the detection of attacks has been performed for several decades, today´s systems are not able to cope with modern attack vectors. One of the reasons is the increasing use of encrypted communication that strongly limits the detection of malicious activities. While encryption provides a number of significant advantages for the end user like, for example, an increased level of privacy, many classical approaches of intrusion detection fail. Since it is typically not possible to decrypt the traffic, performing analysis w.r.t. the presence of certain patterns is almost impossible. To overcome this shortcoming we present a new behavior-based detection architecture that uses similarity measurements to detect intrusions as well as insider activities like data exfiltration in encrypted environments.
Keywords :
Internet; computer network security; cryptography; Internet; behavior-based intrusion detection; data exfiltration; encrypted communication; encrypted environments; malicious activity detection; Encryption; Internet; Intrusion detection; Knowledge based systems; Payloads; Telecommunication network management;
fLanguage :
English
Journal_Title :
Communications Magazine, IEEE
Publisher :
ieee
ISSN :
0163-6804
Type :
jour
DOI :
10.1109/MCOM.2014.6852093
Filename :
6852093
Link To Document :
بازگشت