Extracting ambiguous sessions from real traffic with intrusion prevention systems

I. Ming Chen, Po‐Ching Lin, Tsung-Huan Cheng, Chi-Chung Luo, Ying–Dar Lin, Yuan‐Cheng Lai, Frank C. Lin · 2012

of the systems could judge better than others all the time. This work proposes a system of Ambiguous Session Extraction (ASE) to create a pool of ambiguous traffic traces. Traffic traces or sessions are called “ambiguous”, meaning they cause potential FNs (abbreviated as P-FNs) and potential FPs (abbreviated as P-FPs) to IPSes. IPS developers can use these ambiguous traffic traces to improve the accuracy of their products. The key objective here is to design the ASE system to extract the traces as complete and pure as possible, which gives IPS developers resources for further analysis. First, the ASE captures real traffic and replays captured traffic traces to multiple IPSes. By comparing the logs of IPSes, we might find that some sessions are logged or not logged only at a certain IPS. The former is P-FPs, while the latter is P-FNs

Read the paper · More papers on PaperTik