Authors
Simon P Chung, Aloysius K Mok
Publication date
2007
Conference
Recent Advances in Intrusion Detection: 10th International Symposium, RAID 2007, Gold Goast, Australia, September 5-7, 2007. Proceedings 10
Pages
236-255
Publisher
Springer Berlin Heidelberg
Description
As research in automatic signature generators (ASGs) receives more attention, various attacks against these systems are being identified. One of these attacks is the “allergy attack” which induces the target ASG into generating harmful signatures to filter out normal traffic at the perimeter defense, resulting in a DoS against the protected network. It is tempting to attribute the success of allergy attacks to a failure in not checking the generated signatures against a corpus of known “normal” traffic, as suggested by some researchers. In this paper, we argue that the problem is more fundamental in nature; the alleged “solution” is not effective against allergy attacks as long as the normal traffic exhibits certain characteristics that are commonly found in reality. We have come up with two advanced allergy attacks that cannot be stopped by a corpus-based defense. We also propose a page-rank-based metric for …
Total citations
2007200820092010201120122013201420152016201720182019202020212022153873564125212
Scholar articles
SP Chung, AK Mok - Recent Advances in Intrusion Detection: 10th …, 2007