• Home
  • Search
  • Improving Signature Testing through Dynamic Data Flow Analysis
  • Cite Icon8
  • https://doi.org/10.1109/acsac.2007.40Copy DOI Icon

Improving Signature Testing through Dynamic Data Flow Analysis

  • Dec 1, 2007
  • Christopher Kruegel +3 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

The effectiveness and precision of network-based intrusion detection signatures can be evaluated either by direct analysis of the signatures (if they are available) or by using black-box testing (if the system is closed-source). Recently, several techniques have been proposed to generate test cases by automatically deriving variations (or mutations) of attacks. Even though these techniques have been useful in identifying "blindspots" in the signatures of closed-source, network-based intrusion detection systems, the generation of test cases is performed in a random, un- guided fashion. The reason is that there is no information available about the signatures to be tested. As a result, identifying a test case that is able to evade detection is difficult. In this paper, we propose a novel approach to drive the generation of test cases by using the information gathered by analyzing the dynamic behavior of the intrusion detection system. Our approach applies dynamic dataflow analysis techniques to the intrusion detection system to identify which parts of a network stream are used to detect an attack and how these parts are matched by a signature. The result of our analysis is a set of constraints that is used to guide the black-box testing process, so that the mutations are applied to only those parts of the attack that are relevant for detection. By doing this, we are able to perform a more focused generation of the test cases and improve the process of identifying an attack variation that evades detection.

Similar Papers
  • Conference Article
  • Citations44

Using data mining to discover signatures in network-based intrusion detection

  • Nov 04, 2002
  • Hong Han +2
  • Research Article
  • Citations92

LIO-IDS: Handling class imbalance using LSTM and improved one-vs-one technique in intrusion detection system

  • Apr 07, 2021
  • Computer Networks
  • Neha Gupta +2
  • Research Article
  • Citations23

Data mining aided signature discovery in network-based intrusion detection system

  • Oct 01, 2002
  • ACM SIGOPS Operating Systems Review
  • Hong Han +4
  • Conference Article
  • Citations11

Weaknesses and strengths analysis over network-based intrusion detection and prevention systems

  • Sep 01, 2009
  • Edward Guillen +2
  • Single Report
  • Citations2

Making Network Intrusion Detection Work With IPsec

  • May 11, 2007
  • C D Mclain +2
  • Book Chapter
  • Citations96

Fundamentals of Network Security

  • Feb 28, 2020
  • John E Canavan
  • PDF
  • Research Article
  • Citations48

Using Deep Learning Networks to Identify Cyber Attacks on Intrusion Detection for In-Vehicle Networks

  • Jul 12, 2022
  • Electronics
  • Hsiao-Chung Lin +4
  • Research Article
  • Citations22

Network-based intrusion detection using deep learning technique.

  • Jul 15, 2025
  • Scientific reports
  • Muhammad Farhan +7
  • Conference Article
  • Citations3

Analysing Behaviours for Intrusion Detection

  • Jun 01, 2015
  • George Mamalakis +2
  • Research Article

Multiclass cyber-attack classification approach based on the Krill Herd Optimized Deep Neural Network (KH-DNN) model for WSN

  • Apr 21, 2022
  • International Journal of Modeling, Simulation, and Scientific Computing
  • Samleti Sandeep Dwarkanath +1
  • Research Article
  • Citations2

Collaborative Intrusion Detection System with Snort Machine Learning Plugin

  • Sep 30, 2024
  • JOIV : International Journal on Informatics Visualization
  • Dimas Febriyan Priambodo +5
  • Research Article
  • Citations2

A SURVEY ON NETWORK-BASED INTRUSION DETECTION SYSTEMS USING MACHINE LEARNING ALGORITHMS

  • Jan 01, 2022
  • International Journal of Engineering Applied Sciences and Technology
  • Amin Lama +1
  • Conference Article
  • Citations10

Early Detection of Intrusion in SDN

  • May 08, 2023
  • Md Shamim Towhid +1
  • PDF
  • Research Article
  • Citations105

Performance Assessment of Supervised Classifiers for Designing Intrusion Detection Systems: A Comprehensive Review and Recommendations for Future Research

  • Mar 23, 2021
  • Mathematics
  • Ranjit Panigrahi +6
  • PDF
  • Research Article
  • Citations18

A new intrusion detection and alarm correlation technology based on neural network

  • May 02, 2019
  • EURASIP Journal on Wireless Communications and Networking
  • Yansong Liu +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.