Attacks Detection Based on IP and TCP Protocols Violation

Norma Gomes, Luiz A. Frota Mattos · The International Journal of Forensic Computer Science · 2006

One of the biggest challenges in the network intrusion detection field is the limitation imposed by the use of well-known attack signatures that disable the previous detection of new attacks. This work presents a packet analysis methodology for detecting anomalous behaviors, not based on attack signatures, but on verifying whether the network protocols are being violated, and on the content of the respective headers. The biggest benefit of this methodology is the possibility of detecting anomalies or inadequate behaviors that can correspond, totally or partially, to variations on well-known and unknown attacks.

Read the paper · More papers on PaperTik