Files
notes/docs/lectures/security/15_intrusion_detection.md
T

6.0 KiB
Raw Blame History

Anti-Virus

  • Signature-based detection
    • Store some small code signature for each virus
    • Scan files either in bulk or at run-time, compare with the signatures on file
    • Generic signatures
    • Hashing the entire file is a bad idea, the author only needs to add a nop to completely change the signature
      • Also hashing every executable is slow
    • Instead we identify key pieces of the malware and hash that
    • 1648478154.png
    • This method is never going to catch a virus it’s never seen before
  • Heuristics
    • Determine what actions and rules a virus program will normally adopt
    • Start the program in a VM and see what it does
    • Theoretically could detect a virus that doesn’t strictly match some signature
      • Only if it does the same thing as a virus its seen before
    • A lot slower than signature detection as it needs to be run in a VM before the user is allowed to open it
      • What if the virus sleeps for 20 seconds before doing anything? very hard to detect
  • Machine learning
    • 1648478649.png

Network Attack Models

  • Firewalls don’t protect against
    • Attacks using valid protocols
    • Insider attacks

Intrusion Detection Systems (IDS)

  • Detects possible intrusion attempts
  • Generates alerts and logs for administrators

Intrusion Prevention Systems (IPS)

  • Identical to IDS except also stops the attack

IDS Deployment

  • Host-based (HIDS)
    • Monitors a single host to find suspicious activity including resource / app usage
    • In many ways modern anti-virus does this
    • Additional layer of security software running on a host within a protected LAN or VPN
    • Creates a profile of usage for specific users
    • Can monitor CPU, memory use, application use and the network stack
  • Network-based (NIDS)
    • Monitors network traffic and analyses packets from different protocols to identify suspicious activity
    • Placed at a viewpoint on a network to examine and analyse traffic
      • Installed on a firewall or in a DMZ
      • Installed behind a screened subnet
    • May perform deeper analysis than many firewalls
      • like stateful protocol analysis and deep packet inspection
Components of a IDS
  • Sensors / Agents: collect and collate data from multiple viewpoints on a network
  • Analysers: ascertain if an intrusion has taken place
  • Reporting: notify the administrators via alerts on a console or graphical interface

Multiple sensors allow us to distribute capture, but centralise computing overhead

Detection Modes
  • Stateful Protocol analysis
    • More complex version of a stateful packet filter
    • Hold detailed session information on protocols being used, examine for attacks
      • Why is this user logging on as root?
      • Why is this command being send a 1000 byte buffer as a parameter (buffer overflow)
    • Computationally costly and requires the IDS have all possible versions of these protocols defined in its database
  • Signature-based
    • Fingerprinting sequences of operations or packets
    • Like antivirus, signatures are created and stored in a database - operations as well as binaries
    • If operations match a defined singature, then an alarm is triggered
    • Include some form of attack language
      • Mechanisms to describe sequences of events
      • Maintain and monitor intermediate states and event transitions
    • The pros and cons of these systems are identical to their anti-virus counterpart
      • Computationally efficient
      • Always spots know attacks
      • Always misses unknown attacks
      • Detailed signature databases must be kept up-to-date
    • Example: If there is a large amount of ICMP traffic, many TCP packets (SYN packets)
      • These connections going to a variety of other hosts
    • If a host establishes more than 3 tcp connections to different hosts in 5 seconds, its port scanning
  • Anomaly-based
    • Built a model of normal and find deviations
    • Anomaly detection has wide-ranging application from IDS to banking fraud
    • Build up a picture of normal usage, and detect when usage moves beyond what is normal
    • Always a trade off between false positives and false negatives
    • 1648481248.png
    • Run a host within a quarantined environment and collect training data
    • Constructed by monitoring audit logs
    • Sometimes rely on analysis of sequences of system calls through normal behaviour
    • 1648481362.png
      • However network traffic is more complex than a normal curve
    • 1648481744.png
      • Very hard to decide if network traffic is nefarious or not
Snort
  • Snort is a powerful and well established IDS
    • Also free!
  • Uses rules to analyse network packets, and then can provide alerts or logging
  • Snort has built in rules for detecting nmapm a logged scan may look like this:
    • 1648480866.png
    • The machine 10.0.4.1 is sending out packets with incremented port numbers
    • The time stamps on the data show the packets are being sent extremely quickly
    • All these packets are synchronised packets, its not waiting for ACK packets
Nmap Timings
  • You can avoid detection when using nmap by reducing the speed of the scan
  • The makes port scanning very hard to distinguish from general network noise
  • nmap contains 6 timing options
    • paranoid mode leaves 5 minutes between packets
    • insane mode is basically a DDOS attack

Machine Learning

  • Machine learning approaches train a model to make predictions on data
  • Support vector machines, neural networks etc
Neural Networks for ID
  • A network can be pre-trained
  • Sensor measurements are then passed through the network
  • Activations in the specific output neuron signal an alert

1648481908.png

  • Scales badly
    • Search space can increase exponentially
    • Real-time data
  • False negatives
    • Limits in the representation
    • What is normal can change
      • Do we retrain and risk learning an intruders behaviour?