You are here
Automatic Generation of Robust Network Intrusion Detection Signatures
Title: Systems Engineer
Phone: (714) 435-8920
Email: jleon@irvine-sensors.com
Title: VP, Operations
Phone: (714) 444-8760
Email: dsmetana@irvine-sensors.com
Contact: Paul Franzon
Address:
Phone: (919) 515-7351
Type: Nonprofit College or University
Irvine Sensors Corporation (ISC) together with North Carolina State University propose to develop a novel behavioral technique that is capable of detecting network based intrusions, and can then be used to identify signatures for an Intrusion Prevent Engine (IPE). The behavioral technique proposed detects attacks embedded in different network layers using assertions that can be dynamically updated in real time. The technique involves performing deep packet inspection and making access control decisions based on behavioral compliance. Network traffic behavior is modeled by using theories. Our Behavioral IDS use models of correct and incorrect behaviors, rather than search for signatures. Furthermore, most current approaches do not provide application layer defense. In our approach, the network transactions can be verified as being incorrect or correct, by comparing them against a written set of high-level assertions (“theories”) as to proper behavior. This approach has the potential to detect and prevent network based attacks in real time and also permits theories to be updated in real time.
* Information listed above is at the time of submission. *