Intrusion Detection System Testing via Attack Modification Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems, particularly signature recognition-based systems, face challenges in detecting modified attacks that evade detection by altering their structure, leading to vulnerabilities in network security, as there is no standard definition for an attack and ad-hoc approaches fail to anticipate all possible modifications made by malicious intruders.

Innovation Solution

The development of systems and methods to systematically test intrusion detection systems by applying modification rules that generate modified attacks while preserving the semantics of the original attack, allowing for the determination of attack invariants and the sufficiency of signature sets, ensuring detection of all possible modifications and augmenting signatures to cover undetected attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature recognition-based intrusion detection systems are used to detect attacks, then detection capability for known attack patterns is improved, but the system fails to detect modified attacks that evade detection by altering their structure

Engineering Contradiction:
Improvedetection capabilityVSAvoidability to detect modified attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the attack detection problem into multiple dimensions by analyzing attacks at different protocol levels (application, transport, network, data link, physical). This segmentation allows the system to detect modified attacks by examining structural characteristics across multiple layers rather than relying on a single signature pattern.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of analysis by defining attack invariants and structural characteristics that transcend traditional signature matching. Instead of detecting attacks based on surface-level patterns, the system analyzes deeper structural properties such as packet sequences, protocol violations, and behavioral patterns across multiple protocol levels.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If ad-hoc approaches are used to define attacks without a standard definition, then flexibility in handling diverse attack types is improved, but the system cannot anticipate all possible modifications made by malicious intruders

Engineering Contradiction:
Improvehandling of diverse attack typesVSAvoidcompleteness of attack detection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal framework for defining attacks that works across multiple protocol levels and attack types. By establishing a standardized definition of attack invariants and structural characteristics that apply universally across different protocol layers, the system can consistently detect diverse attack types while maintaining the ability to identify all possible modifications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent systematically varies attack parameters across multiple protocol levels to generate modified attack instances for testing. By changing parameters such as packet structure, protocol sequences, and transmission characteristics while maintaining core attack invariants, the system comprehensively tests detection capability against all possible modifications.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If modification rules are applied to generate all possible attack instances for testing, then completeness of IDS evaluation is improved, but the complexity and time required for testing increases significantly

Engineering Contradiction:
Improvecompleteness of IDS evaluationVSAvoidtesting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis by identifying attack invariants and structural characteristics before generating modified attack instances. By pre-defining the essential properties that must be preserved across modifications and the protocol levels to be tested, the system reduces the search space and focuses testing efforts on the most critical attack variations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different testing strategies to different protocol levels based on their specific characteristics. Rather than uniformly testing all possible modifications across all layers, the system tailors the depth and type of modification rules applied to each protocol level (application, transport, network, data link, physical), optimizing testing efficiency while maintaining comprehensive coverage.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7941856B2Systems and methods for testing and evaluating an intrusion detection system
Publication Date: 2011.05.10 WISCONSIN ALUMNI RES FOUND
  • US7941856B2 patent drawing
  • US7941856B2 patent drawing
  • US7941856B2 patent drawing

AI summary

Systems, methods and devices according to this invention include a plurality of defined modification rules for modifying a sequence of packets that form an attack on an intrusion detection system. These modification rules include both rules that expand the number of packets and rules that reduce the number of packets. The reducing rules can be applied to a given attack instance to identify one or more root attack instances. The expanding rules can then be applied to each root attack instance to generate a corpus of modified attack instances. The modification rules can preserve the semantics of the attack, so that any modified attack instance generated from the given attack instance remains a true attack. To test an intrusion detection system, the corpus of modified attack instances can be used to determine whether an intrusion detection system detects every modified attack instance.