DocumentCode :
464213
Title :
Intrusion Detection for Encrypted Web Accesses
Author :
Yamada, Akira ; Miyake, Yutaka ; Takemori, Keisuke ; Studer, Ahren ; Perrig, Adrian
Author_Institution :
KDDI R&D Labs. Inc., Saitama
Volume :
1
fYear :
2007
fDate :
21-23 May 2007
Firstpage :
569
Lastpage :
576
Abstract :
As various services are provided as web applications, attacks against web applications constitute a serious problem. Intrusion detection systems (IDSes) are one solution, however, these systems do not work effectively when the accesses are encrypted by protocols. Because the IDSes inspect the contents of a packet, it is difficult to find attacks by the current IDS. This paper presents a novel approach to anomaly detection for encrypted web accesses. This approach applies encrypted traffic analysis to intrusion detection, which analyzes contents of encrypted traffic using only data size and timing without decryption. First, the system extracts information from encrypted traffic, which is a set comprising data size and timing for each web client. Second, the accesses are distinguished based on similarity of the information and access frequencies are calculated. Finally, malicious activities are detected according to rules generated from the frequency of accesses and characteristics of HTTP traffic. The system does not extract private information or require enormous pre-operation beforehand, which are needed in conventional encrypted traffic analysis. We show that the system detects various attacks with a high degree of accuracy, adopting an actual dataset gathered at a gateway of a network and the DARPA dataset.
Keywords :
Internet; cryptography; HTTP traffic; Web client; anomaly detection; encrypted Web accesses; encrypted traffic analysis; intrusion detection systems; Cryptography; Data mining; Intrusion detection; Laboratories; Network servers; Protocols; Research and development; Telecommunication traffic; Timing; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Information Networking and Applications Workshops, 2007, AINAW '07. 21st International Conference on
Conference_Location :
Niagara Falls, Ont.
Print_ISBN :
978-0-7695-2847-2
Type :
conf
DOI :
10.1109/AINAW.2007.212
Filename :
4221118
Link To Document :
بازگشت