• DocumentCode
    464213
  • Title

    Intrusion Detection for Encrypted Web Accesses

  • Author

    Yamada, Akira ; Miyake, Yutaka ; Takemori, Keisuke ; Studer, Ahren ; Perrig, Adrian

  • Author_Institution
    KDDI R&D Labs. Inc., Saitama
  • Volume
    1
  • fYear
    2007
  • fDate
    21-23 May 2007
  • Firstpage
    569
  • Lastpage
    576
  • Abstract
    As various services are provided as web applications, attacks against web applications constitute a serious problem. Intrusion detection systems (IDSes) are one solution, however, these systems do not work effectively when the accesses are encrypted by protocols. Because the IDSes inspect the contents of a packet, it is difficult to find attacks by the current IDS. This paper presents a novel approach to anomaly detection for encrypted web accesses. This approach applies encrypted traffic analysis to intrusion detection, which analyzes contents of encrypted traffic using only data size and timing without decryption. First, the system extracts information from encrypted traffic, which is a set comprising data size and timing for each web client. Second, the accesses are distinguished based on similarity of the information and access frequencies are calculated. Finally, malicious activities are detected according to rules generated from the frequency of accesses and characteristics of HTTP traffic. The system does not extract private information or require enormous pre-operation beforehand, which are needed in conventional encrypted traffic analysis. We show that the system detects various attacks with a high degree of accuracy, adopting an actual dataset gathered at a gateway of a network and the DARPA dataset.
  • Keywords
    Internet; cryptography; HTTP traffic; Web client; anomaly detection; encrypted Web accesses; encrypted traffic analysis; intrusion detection systems; Cryptography; Data mining; Intrusion detection; Laboratories; Network servers; Protocols; Research and development; Telecommunication traffic; Timing; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications Workshops, 2007, AINAW '07. 21st International Conference on
  • Conference_Location
    Niagara Falls, Ont.
  • Print_ISBN
    978-0-7695-2847-2
  • Type

    conf

  • DOI
    10.1109/AINAW.2007.212
  • Filename
    4221118