Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
My Menu
Saved Items

Incorporation of Application Layer Protocol Syntax into Anomaly Detection

Patrick DüsselContact Information, Christian GehlContact Information, Pavel Laskov3, 4 Contact Information and Konrad RieckContact Information

(3)  Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany
(4)  Wilhelm-Schickard-Institute for Computer Science, University of Tübingen, Tübingen, Germany
Abstract
The syntax of application layer protocols carries valuable information for network intrusion detection. Hence, the majority of modern IDS perform some form of protocol analysis to refine their signatures with application layer context. Protocol analysis, however, has been mainly used for misuse detection, which limits its application for the detection of unknown and novel attacks. In this contribution we address the issue of incorporating application layer context into anomaly-based intrusion detection. We extend a payload-based anomaly detection method by incorporating structural information obtained from a protocol analyzer. The basis for our extension is computation of similarity between attributed tokens derived from a protocol grammar. The enhanced anomaly detection method is evaluated in experiments on detection of web attacks, yielding an improvement of detection accuracy of 49%. While byte-level anomaly detection is sufficient for detection of buffer overflow attacks, identification of recent attacks such as SQL and PHP code injection strongly depends on the availability of application layer context.

Keywords  Anomaly Detection - Protocol Analysis - Web Security


Contact Information Patrick Düssel
Email: duessel@first.fraunhofer.de

Contact Information Christian Gehl
Email: gehl@first.fraunhofer.de

Contact Information Pavel Laskov
Email: laskov@first.fraunhofer.de

Contact Information Konrad Rieck
Email: rieck@first.fraunhofer.de
Fulltext Preview (Small, Large)
Image of the first page of the fulltext

References secured to subscribers.



Export this chapter
Export this chapter as RIS | Text
 
Remote Address: 38.107.191.111 • Server: mpweb02
HTTP User Agent: CCBot/1.0 (+http://www.commoncrawl.org/bot.html)