• DocumentCode
    3040710
  • Title

    Tuning Intrusion Detection to Work with a Two Encryption Key Version of IPsec

  • Author

    Studer, Ahren ; McLain, Cynthia ; Lippmann, Richard

  • Author_Institution
    MIT Lincoln Laboratory, Lexington, MA; Carnegie Mellon University, Pittsburgh, PA
  • fYear
    2007
  • fDate
    29-31 Oct. 2007
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Network-based intrusion detection systems (NIDSs) are one component of a comprehensive network security solution. The use of IPsec, which encrypts network traffic, renders network intrusion detection virtually useless unless traffic is decrypted at network gateways. Host-based intrusion detection systems (HIDSs) can provide some of the functionality of NIDSs but with limitations. HIDSs cannot perform a network-wide analysis and can be subverted if a host is compromised. We propose an approach to intrusion detection that combines HIDS, NIDS, and a version of IPsec that encrypts the header and the body of IP packets separately ("Two-Zone IPsec"). We show that all of the network events currently detectable by the Snort NIDS on unencrypted network traffic are also detectable on encrypted network traffic using this approach. The NIDS detects network-level events that HIDSs have trouble detecting and HIDSs detect application-level events that can\´t be detected by the NIDS.
  • Keywords
    Cryptography; Electrostatic precipitators; Event detection; Intrusion detection; Laboratories; Pattern matching; Payloads; Performance analysis; Protocols; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, 2007. MILCOM 2007. IEEE
  • Conference_Location
    Orlando, FL, USA
  • Print_ISBN
    978-1-4244-1513-7
  • Electronic_ISBN
    978-1-4244-1513-7
  • Type

    conf

  • DOI
    10.1109/MILCOM.2007.4455095
  • Filename
    4455095