Passer à la navigation principale Passer à la recherche Passer au contenu principal

Implementation of a Stateful Network Protocol Intrusion Detection Systems

  • TelecomSud Paris
  • Lamsid/EDF/R and D

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

The deployment of a Network Intrusion Detection System (NIDS) is one of the imperatives for the control of an information system. Today, almost all intrusion detection systems are based on a static vision of network exchanges, whether for detection engines based on signatures or on behavioral models. However, this approach is limited: it does not allow to directly take into account past exchanges and thus to fully model normal or abnormal behavior, such as verifying that an authentication has taken place before authorizing a privileged request or detecting a replay attack. We propose to add an additional dimension to NIDS by performing stateful monitoring of communication protocols. Unified Modeling Language (UML) statecharts have been chosen to model the protocols and to perform the stateful monitoring. An implementation of this solution is integrated within an existing NIDS and validated on two industrial protocols IEC 60870-5-104 and Modbus TCP. This implementation has been realized by dissociating the stateful monitoring and the NIDS with the help of an abstraction interface allowing an easy integration of new communication protocols.

langue originaleAnglais
titreSECRYPT 2022 - Proceedings of the 19th International Conference on Security and Cryptography
rédacteurs en chefSabrina De Capitani di Vimercati, Pierangela Samarati
EditeurScience and Technology Publications, Lda
Pages398-405
Nombre de pages8
ISBN (imprimé)9789897585906
Les DOIs
étatPublié - 1 janv. 2022
Modification externeOui
Evénement19th International Conference on Security and Cryptography, SECRYPT 2022 - Lisbon, Portugal
Durée: 11 juil. 202213 juil. 2022

Série de publications

NomProceedings of the International Conference on Security and Cryptography
Volume1
ISSN (imprimé)2184-7711

Une conférence

Une conférence19th International Conference on Security and Cryptography, SECRYPT 2022
Pays/TerritoirePortugal
La villeLisbon
période11/07/2213/07/22

Empreinte digitale

Examiner les sujets de recherche de « Implementation of a Stateful Network Protocol Intrusion Detection Systems ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation