Network Intrusion Detection in Encrypted Traffic | IEEE Conference Publication | IEEE Xplore

Network Intrusion Detection in Encrypted Traffic


Abstract:

Traditional signature-based intrusion detection systems inspect packet headers and payloads to report any malicious or abnormal traffic behavior that is observed in the n...Show More

Abstract:

Traditional signature-based intrusion detection systems inspect packet headers and payloads to report any malicious or abnormal traffic behavior that is observed in the network. With the advent and rapid adoption of network encryption mechanisms, typical deep packet inspection systems that focus only on the processing of network packet payload contents are gradually becoming obsolete. Advancing intrusion detection tools to be also effective in encrypted networks is crucial. In this work, we propose a signature language indicating packet sequences. Signatures detect events of possible intrusions and malicious actions in encrypted networks using packet metadata. We demonstrate the effectiveness of this methodology using different tools for penetrating vulnerable web servers and a public dataset with traffic that originates from IoT malware. We implement the signature language and we integrate it into an intrusion detection system. Using our proposed methodology, the generated signatures can effectively and efficiently report intrusion attempts.
Date of Conference: 22-24 June 2022
Date Added to IEEE Xplore: 26 September 2022
ISBN Information:
Conference Location: Edinburgh, United Kingdom

Contact IEEE to Subscribe

References

References is not available for this document.