Tolerating overload attacks against packet capturing systems

Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P. Markatos · 2012

Passive network monitoring applications such as in-trusion detection systems are susceptible to overloads, which can be induced by traffic spikes or algorithmic sin-gularities triggered by carefully crafted malicious pack-ets. Under overload conditions, the system may consume all the available resources, dropping most of the moni-tored traffic until the overload condition is resolved. Un-fortunately, such an awkward response to overloads may be easily capitalized by attackers who can intentionally overload the system to evade detection. In this paper we propose Selective Packet Paging (SPP), a two-layer memory management design that gracefully responds to overload conditions by storing se-lected packets in secondary storage for later processing, while using randomization to avoid predictable evasion by sophisticated attackers. We describe the design and implementation of SPP within the widely used Libpcap packet capture library. Our evaluation shows that the de-tection accuracy of Snort on top of Libpcap is signifi-cantly reduced under algorithmic complexity and traffic overload attacks, while SPP makes it resistant to both al-gorithmic overloads and traffic bursts. 1

Read the paper · More papers on PaperTik