### Anti-Virus - Signature-based detection - Store some small code signature for each virus - Scan files either in bulk or at run-time, compare with the signatures on file - Generic signatures - Hashing the entire file is a bad idea, the author only needs to add a `nop` to completely change the signature - Also hashing every executable is slow - Instead we identify key pieces of the malware and hash that - ![1648478154.png](img/1648478154.png) - This method is never going to catch a virus it’s never seen before - Heuristics - Determine what actions and rules a virus program will normally adopt - Start the program in a `VM` and see what it does - Theoretically could detect a virus that doesn’t strictly match some signature - Only if it does the same thing as a virus it’s seen before - A lot slower than signature detection as it needs to be run in a VM before the user is allowed to open it - What if the virus sleeps for 20 seconds before doing anything? very hard to detect - Machine learning - ![1648478649.png](img/1648478649.png) ### Network Attack Models - Firewalls don’t protect against - Attacks using valid protocols - Insider attacks Intrusion **Detection** Systems (IDS) - Detects possible intrusion attempts - Generates alerts and logs for administrators Intrusion **Prevention** Systems (IPS) - Identical to IDS except also stops the attack #### IDS Deployment - Host-based (HIDS) - Monitors a *single host* to find suspicious activity including resource / app usage - In many ways modern anti-virus does this - Additional layer of security software running on a host within a protected LAN or VPN - Creates a profile of usage for specific users - Can monitor CPU, memory use, application use and the network stack - Network-based (NIDS) - Monitors **network traffic** and analyses packets from different protocols to identify suspicious activity - Placed at a viewpoint on a network to examine and analyse traffic - Installed on a firewall or in a DMZ - Installed behind a screened subnet - May perform deeper analysis than many firewalls - like stateful protocol analysis and deep packet inspection ##### Components of an IDS - Sensors / Agents: collect and collate data from multiple viewpoints on a network - Analysers: ascertain if an intrusion has taken place - Reporting: notify the administrators via alerts on a console or graphical interface > Multiple sensors allow us to **distribute capture**, but **centralise** computing **overhead** ##### Detection Modes - **Stateful Protocol analysis** - More complex version of a stateful packet filter - Hold detailed session information on protocols being used, examine for attacks - Why is this user logging on as root? - Why is this command being sent a 1000-byte buffer as a parameter (buffer overflow) - Computationally costly and requires the IDS to have all possible versions of these protocols defined in its database - **Signature-based** - Fingerprinting sequences of operations or packets - Like antivirus, signatures are created and stored in a database - operations as well as binaries - If operations match a defined signature, then an alarm is triggered - Include some form of attack language - Mechanisms to describe sequences of events - Maintain and monitor intermediate states and event transitions - The pros and cons of these systems are identical to their anti-virus counterpart - Computationally efficient - Always spots known attacks - Always misses unknown attacks - Detailed signature databases must be kept up-to-date - Example: If there is a large amount of `ICMP` traffic, many `TCP` packets (`SYN` packets) - These connections going to a variety of other hosts - *If a host establishes more than 3 tcp connections to different hosts in 5 seconds, it’s port scanning* - **Anomaly-based** - Build a model of *normal* and find deviations - Anomaly detection has wide-ranging application from IDS to banking fraud - Build up a picture of normal usage, and detect when usage moves beyond what is normal - Always a trade-off between **false positives** and **false negatives** - ![1648481248.png](img/1648481248.png) - Run a host within a quarantined environment and collect training data - Constructed by monitoring audit logs - Sometimes rely on analysis of sequences of system calls through normal behaviour - ![1648481362.png](img/1648481362.png) - However network traffic is more complex than a normal curve - ![1648481744.png](img/1648481744.png) - Very hard to decide if network traffic is nefarious or not ###### Snort - Snort is a powerful and well established IDS - Also free! - Uses rules to analyse network packets, and then can provide alerts or logging - Snort has built-in rules for detecting `nmap`; a logged scan may look like this: - ![1648480866.png](img/1648480866.png) - The machine `10.0.4.1` is sending out packets with incremented port numbers - The time stamps on the data show the packets are being sent extremely quickly - All these packets are synchronised packets; it’s not waiting for `ACK` packets ###### Nmap Timings - You can avoid detection when using `nmap` by reducing the speed of the scan - This makes port scanning very hard to distinguish from general network noise - `nmap` contains 6 timing options - paranoid mode leaves 5 minutes between packets - insane mode is basically a DDOS attack #### Machine Learning - Machine learning approaches train a model to make predictions on data - Support vector machines, neural networks etc ##### Neural Networks for ID - A network can be pre-trained - Sensor measurements are then passed through the network - Activations in the specific output neuron signal an alert ![1648481908.png](img/1648481908.png) - Scales badly - Search space can increase exponentially - Real-time data - False negatives - Limits in the representation - What is normal can change - Do we retrain and risk learning an intruder’s behaviour?