6.2 KiB
Anti-Virus
-
Signature-based detection
-
Store some small code signature for each virus
-
Scan files either in bulk or at run-time, compare with the signatures on file
-
Generic signatures
-
Hashing the entire file is a bad idea, the author only needs to add a
nopto completely change the signature- Also hashing every executable is slow
-
Instead we identify key pieces of the malware and hash that
-
This method is never going to catch a virus it’s never seen before
-
-
Heuristics
- Determine what actions and rules a virus program will normally adopt
- Start the program in a
VMand see what it does - Theoretically could detect a virus that doesn’t strictly match some signature
- Only if it does the same thing as a virus it’s seen before
- A lot slower than signature detection as it needs to be run in a VM before the user is allowed to open it
- What if the virus sleeps for 20 seconds before doing anything? very hard to detect
-
Machine learning
Network Attack Models
- Firewalls don’t protect against
- Attacks using valid protocols
- Insider attacks
Intrusion Detection Systems (IDS)
- Detects possible intrusion attempts
- Generates alerts and logs for administrators
Intrusion Prevention Systems (IPS)
- Identical to IDS except also stops the attack
IDS Deployment
- Host-based (HIDS)
- Monitors a single host to find suspicious activity including resource / app usage
- In many ways modern anti-virus does this
- Additional layer of security software running on a host within a protected LAN or VPN
- Creates a profile of usage for specific users
- Can monitor CPU, memory use, application use and the network stack
- Network-based (NIDS)
- Monitors network traffic and analyses packets from different protocols to identify suspicious activity
- Placed at a viewpoint on a network to examine and analyse traffic
- Installed on a firewall or in a DMZ
- Installed behind a screened subnet
- May perform deeper analysis than many firewalls
- like stateful protocol analysis and deep packet inspection
Components of an IDS
- Sensors / Agents: collect and collate data from multiple viewpoints on a network
- Analysers: ascertain if an intrusion has taken place
- Reporting: notify the administrators via alerts on a console or graphical interface
Multiple sensors allow us to distribute capture, but centralise computing overhead
Detection Modes
- Stateful Protocol analysis
- More complex version of a stateful packet filter
- Hold detailed session information on protocols being used, examine for attacks
- Why is this user logging on as root?
- Why is this command being sent a 1000-byte buffer as a parameter (buffer overflow)
- Computationally costly and requires the IDS to have all possible versions of these protocols defined in its database
- Signature-based
- Fingerprinting sequences of operations or packets
- Like antivirus, signatures are created and stored in a database - operations as well as binaries
- If operations match a defined signature, then an alarm is triggered
- Include some form of attack language
- Mechanisms to describe sequences of events
- Maintain and monitor intermediate states and event transitions
- The pros and cons of these systems are identical to their anti-virus counterpart
- Computationally efficient
- Always spots known attacks
- Always misses unknown attacks
- Detailed signature databases must be kept up-to-date
- Example: If there is a large amount of
ICMPtraffic, manyTCPpackets (SYNpackets)- These connections going to a variety of other hosts
- If a host establishes more than 3 tcp connections to different hosts in 5 seconds, it’s port scanning
- Anomaly-based
-
Build a model of normal and find deviations
-
Anomaly detection has wide-ranging application from IDS to banking fraud
-
Build up a picture of normal usage, and detect when usage moves beyond what is normal
-
Always a trade-off between false positives and false negatives
-
Run a host within a quarantined environment and collect training data
-
Constructed by monitoring audit logs
-
Sometimes rely on analysis of sequences of system calls through normal behaviour
-
- However network traffic is more complex than a normal curve
-
- Very hard to decide if network traffic is nefarious or not
-
Snort
-
Snort is a powerful and well established IDS
- Also free!
-
Uses rules to analyse network packets, and then can provide alerts or logging
-
Snort has built-in rules for detecting
nmap; a logged scan may look like this:
Nmap Timings
- You can avoid detection when using
nmapby reducing the speed of the scan - This makes port scanning very hard to distinguish from general network noise
nmapcontains 6 timing options- paranoid mode leaves 5 minutes between packets
- insane mode is basically a DDOS attack
Machine Learning
- Machine learning approaches train a model to make predictions on data
- Support vector machines, neural networks etc
Neural Networks for ID
- A network can be pre-trained
- Sensor measurements are then passed through the network
- Activations in the specific output neuron signal an alert
- Scales badly
- Search space can increase exponentially
- Real-time data
- False negatives
- Limits in the representation
- What is normal can change
- Do we retrain and risk learning an intruder’s behaviour?






