Measured Features for Detecting Attacks

Measured Features for Detecting Attacks

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Measured Features for Detecting Attacks simon 06-19-2008
Posted by simon on June 19, 2008, 1:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi, I find that many network attacks can be detected by measuring one
single feature. For example, the SYN Flood can be detected by counting
the number of SYN packets sent to a destination address. The measured
feature is the number of SYN packets.

Is there an attack that should be detected by at least two features?
Can anyone give me an example and the relevant features?

Thanks a lot!

Simon

Posted by Ertugrul =?UTF-8?B?U8O2eWxlbWV on June 20, 2008, 6:50 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> Hi, I find that many network attacks can be detected by measuring one
> single feature. For example, the SYN Flood can be detected by counting
> the number of SYN packets sent to a destination address. The measured
> feature is the number of SYN packets.
>
> Is there an attack that should be detected by at least two features?
> Can anyone give me an example and the relevant features?

You should be more accurate as to what a "feature" is, but I can give
you two examples of attacks, which require measuring as many features as
possible.

1. Man in the middle (MITM) attack: A perfect MITM attack against a
non-authenticated cryptosystem is impossible to detect. All features
you measure only give evidences.

2. Side channel attack: In an ideal case for the attacker, a side
channel attack is impossible to detect. All features you measure only
give evidences.


Greets,
Ertugrul.


--
http://ertes.de/


Similar ThreadsPosted
Detecting rootkits? June 25, 2005, 10:13 pm
Detecting eBlaster October 7, 2005, 1:30 pm
Can/do PC power saving features effectively turn off ZA and MNW ? August 25, 2005, 1:58 am
Patches and attacks October 6, 2005, 2:33 pm
article on cyber attacks March 20, 2007, 10:57 am
On sci.crypt: New attacks on the financial PIN processing December 1, 2006, 10:32 am
Types of Attacks possible on a home computer.. April 8, 2007, 12:47 am
Re: Targeted trojan attacks via Word flaw May 24, 2006, 1:55 am
TROJAN-HORSE ATTACKS INCREASING, HITTING U.S., WORLDWIDE June 25, 2005, 3:59 pm
Device Authentication - The answer to attacks lauched using stolen passwords? September 2, 2006, 7:44 pm

The site map in XML format XML site map

Contact Us | Privacy Policy