Inproceedings,

Automatically Evading IDS using GP Authored Attacks

, , and .
IEEE Symposium on computational Intelligence in Security and Defense Applications, page 153--160. Honolulu, IEEE Press, (April 2007)

Abstract

A mimicry attack is a type of attack where the basic steps of a minimalist core attack are used to design multiple attacks achieving the same objective from the same application. Research in mimicry attacks is valuable in determining and eliminating weaknesses of detectors. In this work, we provide a genetic programming based automated process for designing all components of a mimicry attack relative to the Stide detector under a vulnerable Traceroute application. Results indicate that the automatic process is able to generate mimicry attacks that reduce the alarm rate from 65percent of the original attack, to 2.7percent, effectively making the attack indistinguishable from normal behaviors.

Tags

Users

  • @brazovayeye

Comments and Reviews