Network Intrusion Detection System with Stream Follow Capability for HTTP/2 and TLS/TCP

S. Sudha, M.Muthamil Jothi, S. Pavalarajan, S. Sutharshan, Godiswary Paramasivam · 2025

Network Intrusion Detection Systems (NIDS), focus on monitoring and analyzing network traffic to identify malicious activities and policy violations. With the evolution of network protocols, traditional NIDS face challenges in handling newer technologies like HTTP/2 and TLS/TCP, leading to delayed detection and insufficient insights into complex network interactions. This study introduces the concept of stream-follow capability, allowing NIDS to efficiently track and analyze multilayered and encrypted traffic streams, such as those found in HTTP/2 and TLS/TCP protocols. By facilitating real-time analysis of encrypted traffic, this feature enhances NIDS capability to identify intrusions in secure, high-layered networks. Encryption is both a boon and challenge in network security. While it secures user data from unauthorized eavesdropping, it also complicates the task of NIDS to examine the content of network traffic. Techniques like SSL/TLS decryption, if allowed, or metadata and behavioural analysis are more commonly used. NIDSs must change from being only data-inspection focused to anomalies in traffic patterns, handshake sequences, and session durations, which could be indicative of potential threats in an encrypted environment.

Read the paper · More papers on PaperTik