【24h】

SafeCard: A Gigabit IPS on the Network Card

机译:SafeCard:网卡上的千兆IPS

获取原文
获取原文并翻译 | 示例

摘要

Current intrusion detection systems have a narrow scope. They target flow aggregates, reconstructed TCP streams, individual packets or application-level data fields, but no existing solution is capable of handling all of the above. Moreover, most systems that perform payload inspection on entire TCP streams are unable to handle gigabit link rates. We argue that network-based intrusion detection systems should consider all levels of abstraction in communication (packets, streams, layer-7 data units, and aggregates) if they are to handle gigabit link rates in the face of complex application-level attacks such as those that use evasion techniques or polymorphism. For this purpose, we developed a framework for network-based intrusion prevention at the network edge that is able to cope with all levels of abstraction and can be easily extended with new techniques. We validate our approach by making available a practical system, SafeCard, capable of reconstructing and scanning TCP streams at gigabit rates while preventing polymorphic buffer-overflow attacks, using (up to) layer-7 checks. Such performance makes it applicable in-line as an intrusion prevention system. SafeCard merges multiple solutions, some new and some known. We made specific contributions in the implementation of deep-packet inspection at high speeds and in detecting and filtering polymorphic buffer overflows.
机译:当前的入侵检测系统范围狭窄。它们以流聚合,重构的TCP流,单个数据包或应用程序级别的数据字段为目标,但是现有解决方案无法处理上述所有问题。而且,大多数对整个TCP流执行有效负载检查的系统无法处理千兆位链接速率。我们认为,基于网络的入侵检测系统在面对复杂的应用程序级别的攻击时,如果要处理千兆位链接速率,则应考虑通信中的所有抽象级别(数据包,流,第7层数据单元和聚合)。使用规避技术或多态的技术。为此,我们开发了一个用于在网络边缘进行基于网络的入侵防御的框架,该框架能够应对所有抽象级别,并且可以轻松地通过新技术进行扩展。我们通过提供实用的系统SafeCard来验证我们的方法,该系统能够使用(最多)第7层检查,以千兆位速率重构和扫描TCP流,同时防止多态缓冲区溢出攻击。这样的性能使其可以在线用作入侵防御系统。 SafeCard合并了多种解决方案,其中一些是新的,一些是已知的。我们在高速实施深度数据包检测以及检测和过滤多态缓冲区溢出方面做出了特殊贡献。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号