• DocumentCode
    2081412
  • Title

    An Efficient TCP Reassembler Mechanism for Layer7-aware Network Intrusion Detection/Prevention Systems

  • Author

    Hanaoka, Miyuki ; Kono, Kenji ; Shimamura, Makoto ; Yamaguchi, Satoshi

  • Author_Institution
    Keio Univ., Keio
  • fYear
    2007
  • fDate
    1-4 July 2007
  • Firstpage
    79
  • Lastpage
    86
  • Abstract
    Exploiting layer/ context is an effective approach to improving the accuracy of detecting malicious messages in network intrusion detection/prevention systems (NIDS/NIPSs). Unfortunately layerl-aware NIDS/NIPSs pose crucial implementation issues because they require full TCP/IP reassembly without losing (1) complete prevention, (2) performance, (3) application transparency, or (4) transport transparency. To the best of our knowledge, none of the existing approaches meet all of these requirements. Our store-through does this by forwarding each out-of-order or IP-fragmented packet immediately after copying it even if it has not been checked yet. Although the forwarded packet might turn out to be a part of an attack, the store-through can successfully defend against the attack by blocking one of the subsequent packets. Testing of a prototype in linux kernel 2.4.30 demonstrated that the overhead of our mechanism is negligible compared with that of a simple IP forwarder even with the presence of out-of-order packets.
  • Keywords
    IP networks; security of data; transport protocols; IP-fragmented packet; Linux kernel; TCP reassembler mechanism; application transparency; network intrusion detection; network prevention system; transport transparency; Delay; Intrusion detection; Kernel; Linux; Out of order; Protocols; Prototypes; TCPIP; Telecommunication traffic; Throughput;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computers and Communications, 2007. ISCC 2007. 12th IEEE Symposium on
  • Conference_Location
    Aveiro
  • ISSN
    1530-1346
  • Print_ISBN
    978-1-4244-1520-5
  • Electronic_ISBN
    1530-1346
  • Type

    conf

  • DOI
    10.1109/ISCC.2007.4381605
  • Filename
    4381605