Formal models and tools to improve nids accuracy
Somesh Jha, Barton P. Miller, Shai Rubin · 2006
It is accepted among researchers and industry professionals that the accuracy of current network intrusion detection systems (NIDS) is questionable. It is well known that NIDS generate many false alarms; it is less publicized that NIDS miss equally many real attacks. This dissertation is about improving NIDS accuracy. Our underlying thesis is that formal methods, previously used in areas such as software analysis and protocol verification, can help us evaluate and increase the accuracy of such systems. We address NIDS accuracy from three different directions. First, we develop a testing methodology which has already gained recognition through finding vulnerabilities in commercial systems. Second, we develop a technique to evaluate the accuracy of a NIDS signature. A signature is the core of NIDS accuracy because it specifies how the NIDS should recognize an attack. Last, we develop a method for constructing a novel signature that matches many different variants of the same attack. An important contribution of this dissertation is a principle that underlies our three techniques. These three techniques are based on formal methods: methods that have solid mathematical foundations. For testing purposes, this foundation provides the ability to precisely define the test cases that should be covered. For signature evaluation, this foundation enables iterative improvement of signature accuracy. Last, for signature construction, this foundation enables both precise definition of all attack variants that a signature must identify, and automatic construction of a recognizes that determines whether the network traffic matches the signature. Our techniques are not a panacea for NIDS accuracy. However, we believe that they provide the means to systematically improve it. We, for example, used the methods to improve the accuracy of real network-based intrusion detection systems deployed worldwide.