Design and implement of NDIS based intrusion detection system

Yifeng Zhu · Journal of Shenyang Normal University · 2012

This paper elaborates on some research work trying to enhance the intrusion detecting rate and to reduce false positive and false negative.Based on NDIS intermediate layer driver,incorporating with the mechanism of Protocol Analysis,this paper brings out a new model of IDS.Besides,give implementations on data collecting module(packet capture) and Protocol Analysis module.In the aspect of data collecting,a packet capture module that is based on NDIS intermediate layer driver in Windows is designed and realized.It runs in Windows Kernel mode nearing to NIC driver,so it can reduce the times of duplication to a minimal.Inside IDS module,introduced Protocol Analysis as a pre-processing module which takes the advantage of high discipline of network protocol to enhance detecting rate and reduce false positive and false negative.Separate the Protocol Analysis module to two parts,one in Kernel Mode and the other in User Mode,each realized respectively.The two communicate with each other through event mechanism and file mapping mechanism,which are feature provided by the Windows.Implemented the module in Kernel Mode on the basis of intermediate layer driver.At the end,exposed model to several conventional attacks using the protocol analysis module in Kernel Mode.

Read the paper · More papers on PaperTik