Developing New Approaches for Intrusion Detection in Converged Networks

Juan Chen · InTech eBooks · 2011

An Intrusion Detection System (IDS) is an important evidence collection tool for network forensics analysis.An IDS operates by inspecting both inbound and outbound network activity and identifying suspicious patterns that may be indicative of a network attack.For each suspicious event, IDS software typically records information similar to statistics logged by firewalls and routers (e.g., date and time, source and destination IP addresses, protocol, and basic protocol characteristics), as well as application-specific information (e.g., username, filename, command, and status code).IDS software also records information that indicates the possible intent of the activity [Gra05].IDS data is often the starting point for examining suspicious activity.Not only do IDSs typically attempt to identify malicious network traffic at all transmission control protocol/Internet protocol (TCP/IP) layers, they also can log many data fields (including raw packets) that can be useful in validating events and correlating them with other data sources [Ken06].IDSs are classified into two categories-anomaly detection and misuse (knowledge-based) detection.Anomaly detection systems require the building of profiles for the traffic that commonly traverses a given network.This profile defines an established baseline for the communication and data exchange that is normally seen over a period of time.These systems have several drawbacks: the IDS alerts are not well adapted for forensics investigation (i.e., sometimes vague), they are complicated (i.e., cannot be communicated easily to nontechnical people), and have a high false negative rate.In contrast, misuse detection methods, also known as signature-based detection, look for intrusive activity that matches specific signatures.These signatures are based on a set of rules that match typical patterns and exploits used by attackers to gain access to a network [Fer05].The disadvantage with misuse detection systems is that without a signature, a new attack method will not be detected until a signature can be generated and incorporated.VoIP has had a strong effect on tactical networks by allowing human voice and video to travel over existing packet data networks with traditional data packets.Among the several issues that need to be addressed when deploying this technology, security is perhaps the most critical.General security mechanisms, such as firewalls and Intrusion Detection Systems (IDS), cannot detect or prevent all attacks.Current techniques to detect and counter www.intechopen.comVoIP Technologies 322 attacks against the converged infrastructure are not sufficient; in particular, they are deficient with respect to real-time network intrusion detection, especially where very high dimensional data are involved, because of computational costs.In addition, they are unable to stop/detect unknown, internal attacks, and attacks that come in the body of the messages (e.g., steganophony attacks [Pel09]).It is indispensable to analyze how an attack happened in order to counter it in the future.In order to effectively counter attacks against the converged network, a systematic approach to network forensic collection and analysis of data is necessary.In conducting network forensics investigations in a VoIP environment, the collection of voice packets in real time and the use of automatic mechanisms are fundamental.In this chapter we will study how attacks against the converged network can be automatically detected in order to create a more secure VoIP system.Our primary focus is on attacks that target media and signaling protocol vulnerabilities.To effectively study new approaches for intrusion detection in VoIP, this chapter starts by analyzing the attacks against the VoIP infrastructure from a hybrid architecture perspective, which will give a clear set of use cases to which we can relate these attacks.Then, network forensic challenges on converged networks are analyzed based on the Digital Forensics Research Workshop framework and on the forensic patterns approach.Further, an analysis of the protocol-based intrusion detection method is presented.Then, statistical methods for intrusion detection, such as stream entropy estimation and dimensionality reduction, are discussed.Finally, the converged experimentation testbed used for prototype tools and commercial software testing is introduced.This chapter ends with some conclusions and ideas for future work.

Read the paper · More papers on PaperTik