Snort 2.1 Intrusion Detection 2004
DOI: 10.1016/b978-193183604-3/50016-3
|View full text |Cite
|
Sign up to set email alerts
|

Mucking Around with Barnyard

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1

Citation Types

0
2
0

Publication Types

Select...
2

Relationship

0
2

Authors

Journals

citations
Cited by 2 publications
(2 citation statements)
references
References 0 publications
0
2
0
Order By: Relevance
“…Since a NIDS that performs a stateful TCP inspection (e.g., [3,14]) uses acknowledgments to update its internal TCP state, different orderings of attack packets and acknowledgments induce different TCP states. Hence, even with a limited ability to influence the ordering between attack packets and victim's acknowledgments, an attacker can create an ordering that induces a TCP state in which a NIDS misses an attack (e.g., Snort Evasive-RST vulnerability, Section 6.1).…”
Section: The Attack Application-level Protocol Obviously Ftpmentioning
confidence: 99%
“…Since a NIDS that performs a stateful TCP inspection (e.g., [3,14]) uses acknowledgments to update its internal TCP state, different orderings of attack packets and acknowledgments induce different TCP states. Hence, even with a limited ability to influence the ordering between attack packets and victim's acknowledgments, an attacker can create an ordering that induces a TCP state in which a NIDS misses an attack (e.g., Snort Evasive-RST vulnerability, Section 6.1).…”
Section: The Attack Application-level Protocol Obviously Ftpmentioning
confidence: 99%
“…Snort, a widelyused NIDS [3,28], represents a signature using a set of attributes: packet attributes, like a packet length, and pattern attributes, like a regular expression defined over the attack bytes. A Snort signature corresponds to a single attack event; it does not (and probably cannot) model the entire attack since Snort does not facilitate composition of rules (except for the ability to dynamically invoke rules for logging purposes).…”
Section: Related Workmentioning
confidence: 99%