articleNov 18, 2002Closed access
Mimicry attacks on host-based intrusion detection systems
University of California, Berkeley
Indexed incrossref
Abstract
We examine several host-based anomaly detection systems and study their security against evasion attacks. First, we introduce the notion of a mimicry attack, which allows a sophisticated attacker to cloak their intrusion to avoid detection by the IDS. Then, we develop a theoretical framework for evaluating the security of an IDS against mimicry attacks. We show how to break the security of one published IDS with these methods, and we experimentally confirm the power of mimicry attacks by giving a worked example of an attack on a concrete IDS implementation. We conclude with a call for further research on intrusion detection from both attacker's and defender's viewpoints.
Citation impact
706
total citations
- FWCI
- 17.32
- Percentile
- 100%
- References
- 36
Citations per year
Authors
2Topics & keywords
Topics
Keywords
- Mimicry
- Intrusion detection system
- Computer science
- Host (biology)
- Intrusion prevention system
- Computer security
- Biology
- Ecology
UN Sustainable Development Goals
- Peace, Justice and strong institutions
No related works found for this paper.