作者: Sergio Pastrana Portillo
DOI:
关键词:
摘要: Intrusion Detection Networks (IDNs) constitute a primary element in current cyberdefense systems. IDNs are composed of different nodes distributed among network infrastructure, performing functions such as local detection --mostly by Systems (IDS) --, information sharing with other the IDN, and aggregation correlation data from sources. Overall, they able to detect attacks taking place at large scale or parts simultaneously. have become themselves target advanced cyberattacks aimed bypassing security barrier offer thus gaining control protected system. In order guarantee privacy systems being IDN itself, it is required design resilient architectures for capable maintaining minimum level functionality even when certain bypassed, compromised, rendered unusable. Research this field has traditionally focused on designing robust algorithms IDS. However, almost no attention been paid analyzing overall them. This Thesis provides various contributions research grouped into two main blocks. The first analyze proposals IDS against specific attacks, while third fourth provide mechanisms that remain presence adversaries. contribution, we propose evasion reverse engineering anomaly detectors use classification core engine. These widely studied field, generally claimed be both effective efficient. do not consider potential behaviors incurred adversaries decrease effectiveness efficiency process. We demonstrate using well-known intrusion vulnerable which makes these inappropriate real second contribution discusses randomization countermeasure detectors. Recent works proposed secret (random) hide surface, making harder an adversary. attack query-response analysis showing does security. our Anagram, popular application-layer detector based randomized n-gram analysis. show how adversary can _rst discover used querying carefully constructed payloads then evade detector. difficulties found properly address motivate protect globally, assuming possibility some devising ways allocating countermeasures optimally. so, essential model adversarial capabilities. Thesis, conceptual viewed whose connections internal components determine architecture global defense network. Such abstraction number existing IDNs. Furthermore, also develop builds classical capabilities communication networks allow specify complex nodes. Finally, presents DEFIDNET, framework assess vulnerabilities IDNs, threats exposed, optimal minimize risk considering possible economic operational constraints. uses system models developed earlier together rating procedure evaluates propagation particular throughout entire estimates impacts actions according strategies. assessment search terms involved cost amount mitigated risk. done multi-objective optimization algorithms, offering analyst sets solutions could applied scenarios. -------------------------------------------------------------