articleNov 18, 2002Closed access

Mimicry attacks on host-based intrusion detection systems

University of California, Berkeley

Indexed incrossref

Abstract

We examine several host-based anomaly detection systems and study their security against evasion attacks. First, we introduce the notion of a mimicry attack, which allows a sophisticated attacker to cloak their intrusion to avoid detection by the IDS. Then, we develop a theoretical framework for evaluating the security of an IDS against mimicry attacks. We show how to break the security of one published IDS with these methods, and we experimentally confirm the power of mimicry attacks by giving a worked example of an attack on a concrete IDS implementation. We conclude with a call for further research on intrusion detection from both attacker's and defender's viewpoints.

Citation impact

706
total citations
FWCI
17.32
Percentile
100%
References
36
Citations per year

Authors

2

Topics & keywords

Keywords
  • Mimicry
  • Intrusion detection system
  • Computer science
  • Host (biology)
  • Intrusion prevention system
  • Computer security
  • Biology
  • Ecology
UN Sustainable Development Goals
  • Peace, Justice and strong institutions
No related works found for this paper.