ACM Home Page
Please provide us with feedback. Feedback
Sensor-based intrusion detection for intra-domain distance-vector routing
Full text PdfPdf (268 KB)
Source Conference on Computer and Communications Security archive
Proceedings of the 9th ACM conference on Computer and communications security table of contents
Washington, DC, USA
SESSION: Network security table of contents
Pages: 127 - 137  
Year of Publication: 2002
ISBN:1-58113-612-9
Authors
Vishal Mittal  University of California Santa Barbara
Giovanni Vigna  University of California Santa Barbara
Sponsors
ACM: Association for Computing Machinery
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 2,   Downloads (12 Months): 40,   Citation Count: 5
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/586110.586129
What is a DOI?

ABSTRACT

Detection of routing-based attacks is difficult because malicious routing behavior can be identified only in specific network locations. In addition, the configuration of the signatures used by intrusion detection sensors is a time-consuming and error-prone task because it has to take into account both the network topology and the characteristics of the particular routing protocol in use. We describe an intrusion detection technique that uses information about both the network topology and the positioning of sensors to determine what can be considered malicious in a particular place of the network. The technique relies on an algorithm that automatically generates the appropriate sensor signatures. This paper presents a description of the approach, applies it to an intra-domain distance-vector protocol and reports the results of its evaluation.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
S. Axelsson. Intrusion Detection Systems: A Taxomomy and Survey. Technical Report 99-15, Dept. of Computer Engineering, Chalmers University of Technology, Sweden, March 2000.
 
2
K.A. Bradley, S. Cheung, N. Puketza, B. Mukherjee, and R.A. Olsson. Detecting Disruptive Routers: A Distributed Network Monitoring Approach. In Proceedings of the IEEE Symposium on Security and Privacy, May 1998.
 
3
4
 
5
S. Cheung, K.N. Levitt, and C. Ko. Intrusion Detection for Network Infrastructures. In Proceedings of the 1995 IEEE Symposium on Security and Privacy, Oakland, CA, May 1995.
 
6
M.T. Goodrich. Efficient and Secure Network Routing Algorithms. Provisional patent filing, January 2001.
 
7
 
8
L.T. Heberlein, K. Levitt, and B. Mukherjee. An intrusion-detection system for large-scale networks. In Proceedings of the 15th National Computer Security Conference, Baltimore, MD, October 1992.
 
9
 
10
Y.F. Jou, F. Gong, C. Sargor, X. Wu, F. Wu, H.C. Chang, and F. Wang. Design and Implementation of a Scalable Intrusion Detection System for the Protection of Network Infrastructure. In DARPA Information Survivability Conference and Exposition, January 2000.
 
11
S. Kent, C. Lynn, J. Mikkelson, and K. Seo. Secure Border Gateway Protocol (Secure-BGP) - Real World Performance and Deployment Issues. In Proceedings of the Symposium on Network and Distributed System Security, February 2000.
 
12
S. Kent, C. Lynn, and K. Seo. Secure Border Gateway Protocol (Secure-BGP). IEEE Journal on Selected Areas in Communications, 18(4):582--592, April 2000.
 
13
G. Malkin. Rip version 2. IETF RFC 2453, Nov 1998.
 
14
 
15
 
16
R. Perlman. Network Layer Protocols with Byzantine Robustness. PhD thesis, Department of EECS, MIT, August 1988.
 
17
 
18
Y. Rekhter and T. Li. A border gateway protocol 4 (bgp-4). IETF RFC 1654, Mar 1995.
 
19
B.R. Smith and J.J. Garcia-Luna-Aceves. Securing the Border Gateway Routing Protocol. In Proceedings of Global Internet '96, London, UK, November 1996.
 
20
 
21
 
22
F. Wu, H.C. Chang, F. Jou, F. Wang, F. Gong, C. Sargor, D. Qu, and R. Cleaveland. Jinao: Design and implementation of a scalable intrusion detection system for the ospf routing protocol, February 1999.
 
23
F. Wu, F. Wang, B.M. Vetter, W.R. Cleaveland, F. Jou, F. Gong, and C. Sargor. Intrusion Detection for Link-State Routing Protocols, December 1996.
 
24
K. Zhang. Efficient Protocols for Signing Routing Messages. In Proceedings of the Symposium on Network and Distributed System Security, February 1998.


Collaborative Colleagues:
Vishal Mittal: colleagues
Giovanni Vigna: colleagues