Full metadata record
DC FieldValueLanguage
dc.contributor.authorCheng, Tsung-Huanen_US
dc.contributor.authorLin, Ying-Daren_US
dc.contributor.authorLai, Yuan-Chengen_US
dc.contributor.authorLin, Po-Chingen_US
dc.date.accessioned2014-12-08T15:29:40Z-
dc.date.available2014-12-08T15:29:40Z-
dc.date.issued2012en_US
dc.identifier.issn1553-877Xen_US
dc.identifier.urihttp://hdl.handle.net/11536/21310-
dc.identifier.urihttp://dx.doi.org/10.1109/SURV.2011.092311.00082en_US
dc.description.abstractDetecting attacks disguised by evasion techniques is a challenge for signature-based Intrusion Detection Systems (IDSs) and Intrusion Prevention Systems (IPSs). This study examines five common evasion techniques to determine their ability to evade recent systems. The denial-of-service (DoS) attack attempts to disable a system by exhausting its resources. Packet splitting tries to chop data into small packets, so that a system may not completely reassemble the packets for signature matching. Duplicate insertion can mislead a system if the system and the target host discard different TCP/IP packets with a duplicate offset or sequence. Payload mutation fools a system with a mutative payload. Shellcode mutation transforms an attacker's shellcode to escape signature detection. This study assesses the effectiveness of these techniques on three recent signature-based systems, and among them, explains why Snort can be evaded. The results indicate that duplicate insertion becomes less effective on recent systems, but packet splitting, payload mutation and shellcode mutation can be still effective against them.en_US
dc.language.isoen_USen_US
dc.subjectIDS/IPSen_US
dc.subjectevasionen_US
dc.subjectattacksen_US
dc.subjectsignatureen_US
dc.titleEvasion Techniques: Sneaking through Your Intrusion Detection/Prevention Systemsen_US
dc.typeArticleen_US
dc.identifier.doi10.1109/SURV.2011.092311.00082en_US
dc.identifier.journalIEEE COMMUNICATIONS SURVEYS AND TUTORIALSen_US
dc.citation.volume14en_US
dc.citation.issue4en_US
dc.citation.spage1011en_US
dc.citation.epage1020en_US
dc.contributor.department資訊工程學系zh_TW
dc.contributor.departmentDepartment of Computer Scienceen_US
dc.identifier.wosnumberWOS:000315392500005-
dc.citation.woscount2-
Appears in Collections:Articles


Files in This Item:

  1. 000315392500005.pdf

If it is a zip file, please download the file and unzip it, then open index.html in a browser to view the full text content.