Study on intrusion detection for the small IP packet attack
Xingcheng Liu · Computer Engineering and Applications Journal · 2007
Intrusion detection technology is a new technology in network security area.However,it is still very immature.Many malicious network attack methods make use of its drawbacks to initiate attacks.Small IP packet attack makes use of the difference between Windows and Linux when they deal with the data-overlapped packets.This paper puts forward a method that detects IP packet attacks,performs an experiment using Snort,and makes Snort act the same way as the protected host when they deal with the data-overlapped packets.As a result,the times that Snort misinforms or fails to report attack reduce.The approach provides useful reference for constructing secure network systems.