Files
notes/docs/lectures/security/15_intrusion_detection.md
T
2026-10-04 15:24:17 +01:00

148 lines
6.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
### Anti-Virus
- Signature-based detection
- Store some small code signature for each virus
- Scan files either in bulk or at run-time, compare with the signatures on file
- Generic signatures
- Hashing the entire file is a bad idea, the author only needs to add a `nop` to completely change the signature
- Also hashing every executable is slow
- Instead we identify key pieces of the malware and hash that
- ![1648478154.png](img/1648478154.png)
- This method is never going to catch a virus it’s never seen before
- Heuristics
- Determine what actions and rules a virus program will normally adopt
- Start the program in a `VM` and see what it does
- Theoretically could detect a virus that doesn’t strictly match some signature
- Only if it does the same thing as a virus it’s seen before
- A lot slower than signature detection as it needs to be run in a VM before the user is allowed to open it
- What if the virus sleeps for 20 seconds before doing anything? very hard to detect
- Machine learning
- ![1648478649.png](img/1648478649.png)
### Network Attack Models
- Firewalls don’t protect against
- Attacks using valid protocols
- Insider attacks
Intrusion **Detection** Systems (IDS)
- Detects possible intrusion attempts
- Generates alerts and logs for administrators
Intrusion **Prevention** Systems (IPS)
- Identical to IDS except also stops the attack
#### IDS Deployment
- Host-based (HIDS)
- Monitors a *single host* to find suspicious activity including resource / app usage
- In many ways modern anti-virus does this
- Additional layer of security software running on a host within a protected LAN or VPN
- Creates a profile of usage for specific users
- Can monitor CPU, memory use, application use and the network stack
- Network-based (NIDS)
- Monitors **network traffic** and analyses packets from different protocols to identify suspicious activity
- Placed at a viewpoint on a network to examine and analyse traffic
- Installed on a firewall or in a DMZ
- Installed behind a screened subnet
- May perform deeper analysis than many firewalls
- like stateful protocol analysis and deep packet inspection
##### Components of an IDS
- Sensors / Agents: collect and collate data from multiple viewpoints on a network
- Analysers: ascertain if an intrusion has taken place
- Reporting: notify the administrators via alerts on a console or graphical interface
> Multiple sensors allow us to **distribute capture**, but **centralise** computing **overhead**
##### Detection Modes
- **Stateful Protocol analysis**
- More complex version of a stateful packet filter
- Hold detailed session information on protocols being used, examine for attacks
- Why is this user logging on as root?
- Why is this command being sent a 1000-byte buffer as a parameter (buffer overflow)
- Computationally costly and requires the IDS to have all possible versions of these protocols defined in its database
- **Signature-based**
- Fingerprinting sequences of operations or packets
- Like antivirus, signatures are created and stored in a database - operations as well as binaries
- If operations match a defined signature, then an alarm is triggered
- Include some form of attack language
- Mechanisms to describe sequences of events
- Maintain and monitor intermediate states and event transitions
- The pros and cons of these systems are identical to their anti-virus counterpart
- Computationally efficient
- Always spots known attacks
- Always misses unknown attacks
- Detailed signature databases must be kept up-to-date
- Example: If there is a large amount of `ICMP` traffic, many `TCP` packets (`SYN` packets)
- These connections going to a variety of other hosts
- *If a host establishes more than 3 tcp connections to different hosts in 5 seconds, it’s port scanning*
- **Anomaly-based**
- Build a model of *normal* and find deviations
- Anomaly detection has wide-ranging application from IDS to banking fraud
- Build up a picture of normal usage, and detect when usage moves beyond what is normal
- Always a trade-off between **false positives** and **false negatives**
- ![1648481248.png](img/1648481248.png)
- Run a host within a quarantined environment and collect training data
- Constructed by monitoring audit logs
- Sometimes rely on analysis of sequences of system calls through normal behaviour
- ![1648481362.png](img/1648481362.png)
- However network traffic is more complex than a normal curve
- ![1648481744.png](img/1648481744.png)
- Very hard to decide if network traffic is nefarious or not
###### Snort
- Snort is a powerful and well established IDS
- Also free!
- Uses rules to analyse network packets, and then can provide alerts or logging
- Snort has built-in rules for detecting `nmap`; a logged scan may look like this:
- ![1648480866.png](img/1648480866.png)
- The machine `10.0.4.1` is sending out packets with incremented port numbers
- The time stamps on the data show the packets are being sent extremely quickly
- All these packets are synchronised packets; it’s not waiting for `ACK` packets
###### Nmap Timings
- You can avoid detection when using `nmap` by reducing the speed of the scan
- This makes port scanning very hard to distinguish from general network noise
- `nmap` contains 6 timing options
- paranoid mode leaves 5 minutes between packets
- insane mode is basically a DDOS attack
#### Machine Learning
- Machine learning approaches train a model to make predictions on data
- Support vector machines, neural networks etc
##### Neural Networks for ID
- A network can be pre-trained
- Sensor measurements are then passed through the network
- Activations in the specific output neuron signal an alert
![1648481908.png](img/1648481908.png)
- Scales badly
- Search space can increase exponentially
- Real-time data
- False negatives
- Limits in the representation
- What is normal can change
- Do we retrain and risk learning an intruder’s behaviour?