• DocumentCode
    2383931
  • Title

    An active DES based IDS for ARP spoofing

  • Author

    Barbhuiya, F.A. ; Biswas, S. ; Nandi, S.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., IIT, Guwahati, India
  • fYear
    2011
  • fDate
    9-12 Oct. 2011
  • Firstpage
    2743
  • Lastpage
    2748
  • Abstract
    A network Intrusion Detection System (IDS) is a device or software that monitors network activities and raises alerts on detection of malicious behavior. State-transition based framework like Finite State Machines (FSM), extended FSM, timed FSM, Discrete Event Systems (DES) etc. are widely used in network IDSs because the framework enables formal modeling, analysis, verification etc. The attack detection capability in these IDSs is based on passive monitoring of sequence of events with the assumption that intrusions lead to change in the sequence (which needs to be detected). However, there are certain attacks like ARP spoofing, Internet Control Message Protocol (ICMP) error message based attacks etc. for which passive monitoring schemes have several limitations because in such attacks there is no change in sequence of events. IDSs with active probing are now being proposed for such attacks which involve sending of probe packets that cause difference in sequence of events under attack condition and can be then detected using passive monitoring. In this paper we propose an IDS to detect ARP spoofing attacks using active state-transition framework called “active DES”.
  • Keywords
    computer network security; computer viruses; discrete event systems; finite state machines; formal specification; formal verification; ARP spoofing attacks; ICMP error message based attacks; Internet Control Message Protocol; active DES; attack detection; discrete event systems; extended FSM; finite state machines; formal analysis; formal modeling; formal verification; malicious behavior detection; network IDS; network activity monitoring; network intrusion detection system; passive monitoring; state-transition based framework; timed FSM; Adaptation models; Clocks; IP networks; Local area networks; Monitoring; Probes; Protocols; ARP spoofing; Active Discrete Event System; Failure Detection and Diagnosis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systems, Man, and Cybernetics (SMC), 2011 IEEE International Conference on
  • Conference_Location
    Anchorage, AK
  • ISSN
    1062-922X
  • Print_ISBN
    978-1-4577-0652-3
  • Type

    conf

  • DOI
    10.1109/ICSMC.2011.6084088
  • Filename
    6084088