Network intrusion detection with semantics-aware capability
Walter J. Scheirer, Mooi Choo Chuah · 2006
Abstract – Malicious network traffic, including widespread worm activity, is a growing threat to Internet-connected networks and hosts. The nature of such traffic is constantly changing, as authors of both malicious software and security services compete against each other. In this paper, we propose a network intrusion detection system (NIDS) with semantic-aware capability. Our NIDS segregates suspicious traffic from the regular traffic flow, extracts binary code from the suspicious traffic and performs semantic analysis on it to identify potential threats. Our system consists of a pipeline of five stages. The initial stage classifies suspicious traffic, and passes the suspicious packets to a binary code extraction module. Once relevant binary data is identified and extracted, it is disassembled, and then parsed into an intermediate representation. Next, we try to match code fragments in the intermediate representation form to some preconfigured templates. If a semantic match is found, then we consider that suspicious packet to be malicious. Our contributions in this work are three fold: (a) we believe our prototype is the first NIDS that provides semantic aware capability, (b) our implementation is more efficient than what is reported in [5], (c) our designed templates can capture polymorphic shellcodes with added sequences of stack and mathematic operations. 1.