Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection
Explore this paper's citation graph
Summary
Three classes of attacks which exploit fundamentally problems with the reliability of passive protocol analysis are defined--insertion, evasion and denial of service attacks--and how to apply these three types of attacks to IP and TCP protocol analysis is described.
- Type
- article
- Published
- 1998-01-01
- Cited by
- 861
- References
- 21
- OpenAlex
- https://openalex.org/W1490025813
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:16418229
Keywords
Denial-of-service attack, Computer science, Intrusion detection system, Evasion (ethics), Computer security
References
- Live Traffic Analysis of TCP/IP Gateways
- Bro: a system for detecting network intruders in real-time
- A Simple Active Attack Against TCP
- TCP Extensions for High Performance
- End-to-end Internet packet dynamics
- Security Architecture for the Internet Protocol
- A Methodology for Testing Intrusion Detection Systems
- Authentication server
- Internet Protocol
- Security Architecture for the Internet Protocol
- GrIDS A Graph-Based Intrusion Detection System for Large Networks
- TCP/IP Illustrated
- A common intrusion detection framework
- Transmission control protocol: darpa internet program protocol specification
- Transmission control protocol- darpa internet program protocol specification
- Internet Protocol
Cited by
- Hardware acceleration of network intrusion detection and prevention
- Improving Self Organizing Map Performance for Network Intrusion Detection
- A Framework for Distributed Intrusion Detection using Interest-Driven Cooperative Agents
- Anonymization of real data for IDS benchmarking
- Categorizing Network Attacks Using Pattern Classification Algorithms
- PHAD: packet header anomaly detection for identifying hostile network traffic
- Bro: An Open Source Network Intrusion Detection System
- Evaluation of the Intrusion Detection Capabilities and Performance of a Security Operation Center
- What do we mean by Network Denial of Service
- Modeling NIDS Evasion with Genetic Programming
- Steps for Improving Data Comprehension for Digital Security and Forensics
- Intrusion detection: Forensic computing insights arising from a case study on SNORT
- Generic detection of code injection attacks using network-level emulation
- Therminator : configuring the underlying statistical mechanics model
- Fast Multipattern Matching for Intrusion Detection
- Towards Faster String Matching for Intrusion Detection
- Commercial Internet and the need for security
- Distributed Metastasis : A Computer Network Penetration Methodology
- An Efficient Intrusion Detection System for Networks with Centralized Routing
- An efficient multi-hash pattern matching scheme for intrusion detection in FPGA-based reconfiguring hardware
Related papers
- Vigilante: end-to-end containment of internet worms
- Throttling viruses: restricting propagation to defeat malicious mobile code
- ReVirt: enabling intrusion analysis through virtual-machine logging and replay
- Internet quarantine: requirements for containing self-propagating code
- Dynamic Taint Analysis for Automatic Detection, Analysis, and SignatureGeneration of Exploits on Commodity Software