Dynamic Protocol Analysis for Network Intrusion Detection Systems

Ur Informatik, Michael Mai · 2005

Many Network Intrusion Detection Systems (NIDSs) perform application layer protocol analysis. These systems typically infer the protocol from the ports in the TCP or UDP headers. This is not a reliable technique since many protocols do not use fixed ports. On the other hand there exist better methods to identify used application layer protocols e.g. signatures. In this thesis we present design and implementation of an architecture for NIDSs which supports the integration of these advanced methods for dynamic protocol analysis. The design is suitable for analyzing tunneled connections as well. Our implementation for the open source system Bro uses its existing signature matching engine as additional protocol detection method. On the basis of this prototype we show the results under the aspects of detection rate, need of performance and the interaction of both.

Read the paper · More papers on PaperTik