Validation Methods of Suspicious Network Flows for Unknown Attack Detection
Ikkyun Kim, Daewon Kim, Yangseo Choi, Koohong Kang, Jintae Oh, Jongsoo Jang · 2009
The false rate of the detection methods which are based on abnormal traffic behavior is a little high and the accuracy of the signature generation is relatively low. Moreover, it is not suitable to detect exploits and generate its signature. In this paper, we have presented ZASMIN (Zeroday-Attack Signature Management Infrastructure) system, which is developed for novel network attack detection. This system provides early warning at the moment the attacks start to spread on the network and to block the spread of the cyber attacks by automatically generating a signature that could be used by the network security appliance such as IPS. This system have adopted various technologies — suspicious traffic monitoring, attack validation, polymorphic worm recognition, signature generation — for unknown network attack detection. Especially, the validation functions in ZASMIN have to able to cover 1) polymorphism, which is an encrypted attack code at the penetration and operation step, 2) executables, which are any binary functions at each step, and 3) malicious string. And also, we introduce two concepts to validate the pre- processing of the suspicious traffic. The one is attack-based validation and the other is signature-based validation. These validation functions can reduce the false rate of the unknown attack detection. In order to check the feasibility of the validation functions in ZASMIN, we have installed it on real honeynet environment, then we have analyzed the result about detection of unknown attack. Even though short-period analysis is not enough long to detect various unknown attacks, we confirmed that ZASMIN can detect some attacks without any well-known signature. month. Such wide-spread vulnerabilities in software add to today's insecure computing/networking environment. Similar new vulnerabilities in networks and applications are discov- ered and published on a daily basis. This insecure environment has given rise to the ever evolving field of intrusion detection and prevention. In the classification point of view of the typical network intrusion detection methodology, we can consider the zero- day worm problem as the extension of the anomaly detection methodology. However, as the zero-day network attack became more sophisticated and faster in spreading across network, it differs from the existing anomaly detection methodology and researches. In the initial of this research of a field, it was initiated from the detection and signature generation methods (26), (31), (32) using the content prevalence model which considers the propagation of the super worm including Code-Red, Slammer, etc. But the false rate of the detection methods which are based on it is a little high and the accuracy of the signature generation is relatively low. Moreover, it is not suitable to detect exploits and generate the signature, if we look into the recent trend of new network attacks. For example, after Sasser worm occurred in 2004, the network attack of the similar type markedly decreases. And malicious software mainly spread by using E-mail, downloader, dropper, and etc. Therefore, as to researches (26), (16) using the property of the similarity or the repeatability of the network traffic, the effectiveness decreases, while some static or dynamic analysis method of network packet have gotten the attention in detecting the malicious software. In this paper, we have developed the Zeroday-Attack Sig- nature Management Infrastructure(ZASMIN) system for novel network attack detection. This system provides early detection function and validation of attack at the moment the attacks start to spread on the network. The system could also contain the spread of the cyber attacks by automatically releasing a signature that could be used by the network security appliance such as IPS. In order to detect unknown network attack, the ZASMIN system has adopted various of new technologies, which are composed of suspicious traffic monitoring, attack validation, polymorphic worm recognition, signature gener- ation. Some of these functionalities are implemented with hardware-based accelerator to be able to deal with giga-bit speed traffic, therefore, it can be applicable to Internet back- bone or the bottle-neck point of high-speed enterprize network without any loss of traffic. After we installed the ZASMIN on real honey-net environment in the internet exchange point (IX), we have analyzed the results of the ZASMIN about detection of unknown attack for two days. Even if two-day analysis