Latest News twitter feed
Other News

IIDI Professor Bill Buchanan to present at prestigious British American...

13/05/2012

Read more...
Other News

IIDI Professor Bill Buchanan outlines Excellence in Security and Forensics

10/05/2012

Read more...
Events: Other Event

Alistair Duff discusses the 'info poor' at ICTs-and-Society conference in Sweden

09/05/2012

Read more...
See all news

NetHost-Sensor: Investigating the Capture of End-To-End Encrypted Intrusive Data

Abimbola, A., Munoz, J., Buchanan, W. (2006). NetHost-Sensor: Investigating the Capture of End-To-End Encrypted Intrusive Data. Computers & Security, 25, (6), 445-451.


ISBN:
ISSN: 0167-4048

Abstract

Intrusion Detection Systems (IDSs) are systems that protect against violation of data integrity, confidentiality and availability of resources. In the past 20 years, these systems have evolved with the technology and have become more sophisticated. Despite these advances, IDS is still an immature field, and the benefits obtained from detecting end-to-end encrypted attacks justify the need for more research. This paper presents possible advantages of an IDS that uses a target host's kernel as its audit source for intrusion analysis against specific attacks. In addition, we describe our research experience in determining what layer, within a protocol stack of a target host, where decrypted data can be captured for intrusion detection. Then, it examines how to capture decrypted data, while communicating via an End-to-End (ETE) encryption channel. The paper proceeds further to discuss our methodology using network communication driver interfaces, investigative experimental procedures and present our experimental results. Finally, discussions on the methodology of our future research, modelling HTTP network data via procedure analysis technique to reduce false positive rate of attacks are presented.

Authors

William Buchanan

Professor William Buchanan

Director of CDCS
w.buchanan@napier.ac.uk
+44 131 455 2759

Associated Themes

Security and Cybercrime

Security and Cybercrime

Electronic information now plays a vital role in almost every aspect of our daily lives.


Associated Projects