• No results found

Recent Challenges of Intrusion Detection System

In document Web Services Security & E Business pdf (Page 156-159)

As computer technology advances, IDS needs to keep up in order to function at its best. Computer systems have enhanced to be more complex for processing advanced require- ments. Its speed has increased; data processing and transferring have been leaping tremendously. For IDS to function in real time, it faces challenges to understand complex systems and must be able to extract meaningful data from a pool of data sources. Not only extracting data, but it also needs to extract and analyze it fast. This stands in contrast with batch-mode IDS, where data processing is not necessarily done in real time. Up on the networking-protocol stack, there are more protocols formed to keep up with business needs. For example, Web services have used several XML-based protocols like SOAP protocol. In order to extract any meaningful data, the system must be able to interpret a protocol data unit by inspecting packets all the way up to the upper layer protocol. This is another enormous challenge.

In addition, threats of viruses, worms, and other malicious programs have brought additional challenges to IDS. Those programs have become a constant threat. Not only are they getting sophisticated in distribution and attack mechanism, but they are also spreading fast. According to previous work, flash worm could saturate one million hosts in around 30-seconds time (Staniford, Paxson, & Weaver, 2002). For such a fast spreading mechanism, misuse detection might not be very effective. On the other hand, anomaly detection might perform better for its capability to remember what good behavior is. Inherently, such a system could derive a new vector of attacks.

Signature-based intrusion detection system has been around for sometime. Its operation depends very much on human intervention to supply an accurate signature for attack detection. Its incapability to observe new attacks has been a great disadvantage, especially against zero-day exploit. For that reason, anomaly-based IDS might come to help. Having said that, it does not mean that traditional IDS is dead. On the other hand, it has evolved and integrated into a hybrid of both signature based and anomaly based. For other, IDS has been easily integrated with firewall and other network infrastructure to form what is knows as intrusion prevention system (IPS).

As more people have access to networks, security officers face more obstacles in determining incidents. IDS’s role in detecting attack suffers from false positives and false negatives. False positive signifies symptoms detected by IDS but they are not real attacks. False negative implies certain valid attacks go undetected. With increasingly more events occurring on computer systems, IDS is facing heavy trial to help security staffers in detecting intrusions effectively and efficiently. Lower false positives and capability to detect more attacks have been urgent for IDS like never before.

Conclusion

Intrusion detection system, as security officers’ eyes on a computer system, has been an integrated and important infrastructure for digital information security. From its inception rooted from audit systems, IDS has been able to answer challenges in detecting intrusion. With the initial research trend based on anomaly detection and later on misused schemes, we are now witnessing products that try to apply a hybrid approach in detecting attacks. Signature-based detection has been important for its effectiveness and lower false positives. On the other hand, to answer challenges from newer threats (zero-day attack) that spread fast, anomaly detection could help more. Hence, a hybrid- type of IDS becomes relevant.

To predict that IDS is dead might be a little overboard. Even though declining in general usage, IDS has been functionally merged with other networking nodes. Besides that, its important value of gathering traces to be analyzed by forensics is paramount. For now, IDS has evolved into a more sophisticated system: intrusion prevention system (IPS). Its effectiveness is still being observed.

For the time being, researchers have adequately identified a method of detecting attack that has a common pattern. But the next challenge is to secure a computer system in a way that it is resistant against not only old attacks, but also newer attack vectors.

References

Aho, A.V., & Corasick, M.J. Efficient String Matching: An aid to bibligraphic search. Communications of ACM, 18(6), 33-340.

Amarasinghe, S. (2005). Host-based IPS guards endpoints. Retrieved January 22, 2005, from http://www.networkworld.com/news/tech/2005/072505techupdate.html?fsrc=rss- intrusion

Boyer, R. S., & Moore, J. S. (1977). A fast string searching algorithm. Communications of ACM, 20(10), 762-772.

Cox, J. (2005). School nixes malware with open source. Retrieved from http:// ungoliant.sourceforge.net/

Debar, H., Becker, M., & Siboni, D. (4-6 May, 1992). A neural network component for an intrusion detection system. In Proceedings of the IEEE Symposium on Security and Privacy (pp. 240-250), 1992.

Denning, D. E. (7-9 May, 1986). An intrusion detection model. In Proceedings of the Seventh IEEE Symposium of Security and Privacy, (pp. 118-131).

Heberlein, L. T. (1990). A network security monitor. In Proceedings of the IEEE Symposium on Research in Security and Privacy (pp. 296-304).

Hochberg, J., Jackson, K., Stallings, C., McClary, J. F., DuBois, D., & Ford, J. (1993). NADIR: An automated system for detecting network intrusion and misuse. Com- puters and Security, 12(3), 235-248.

Javitz, H. S., & Valdes, A. (1991). The SRI IDES statistical anomaly detector. In Proceedings IEEE Symposium on Security and Privacy.

Kim, G. H., & Spafford, E. H. (1994). The design and implementation of Tripwire: A file

system integrity checker. In Proceedings of the 2nd ACM Conference on Computer

and Communication Security (pp. 18-29).

Roesch, M. (1999). Snort — Lightweight intrusion detection for networks. In Proceed-

ings of the 13th USENIX LISA Conference, USENIX Association (pp. 229-238).

Sebring, M., Shellhouse, E., Hanna, M. E., & Whitehurst, R. A. (October, 1988). Expert systems in intrusion detection: A case study. In Proceedings of the Eleventh National Computer Security Conference, Baltimore, MD (pp. 74-81).

Smaha, S. E. (12-16 Dec, 1988). Haystack: An intrusion detection system. In Proceedings of the Fourth Aerospace Computer Security Applications Conference, Orlando,

FL (pp. 37-44).

Staniford, S., Paxson, V., & Weaver, N. (August 2002) How to own the Internet in your

spare time. In Proceedings of the 11th USENIX Security Symposium, San Francisco,

CA (149-167).

Tener, W. T. (1986). Discovery: An expert system in the commercial data security environment. In Proceedings of the IFIP Security Conference, Monte Carlo.

Chapter VIII

Node Authentication

In document Web Services Security & E Business pdf (Page 156-159)