• DocumentCode
    1629307
  • Title

    Multi-packet & multi-session signature detection using state based model

  • Author

    Pawar, Pramod S. ; Singh, Mayank Pal ; Narayanan, Sachin

  • Author_Institution
    Comput. Network & Internet Eng.(CNIE), Center For Dev. Of Ad v. Comput.(CDAC), Bangalore, India
  • fYear
    2010
  • Firstpage
    190
  • Lastpage
    194
  • Abstract
    Signature Detection modules in IDS/IPS though accurate in pattern matching, yet it leads to false positives. This is due to the incompleteness of the signatures which lacks or has very little information about when, where and how to match these signatures. The signatures enriched with this information significantly brings down the false positives and at the same time enhances the performance of the signature detection module. In this paper we propose a state base signature detection model which leverages on our state aware signatures with sufficiently complete information to match these signatures. The proposed model keeps track of the state of the connection and matches the signatures within appropriate packets. We further classify our signatures that span across multiple packet and across multiple sessions. We also provide the notion of virtual signatures which represents patterns within packets in a distributed form. In this paper we demonstrate the capabilities of our proposed model to detect these virtual patterns, multi-packet and multi-session leveraging on our state aware signatures.
  • Keywords
    digital signatures; pattern matching; IDS; IPS; multipacket signature detection; multisession signature detection; pattern matching; state aware signatures; state base model; Change detection algorithms; Computer networks; Computer vision; IP networks; Intrusion detection; Pattern matching; Protocols; Search engines; Telecommunication traffic; Multi-Packet; Multi-Session; State Based Model; State Based Signature; component;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advance Computing Conference (IACC), 2010 IEEE 2nd International
  • Conference_Location
    Patiala
  • Print_ISBN
    978-1-4244-4790-9
  • Electronic_ISBN
    978-1-4244-4791-6
  • Type

    conf

  • DOI
    10.1109/IADCC.2010.5423011
  • Filename
    5423011