Anomaly based Detection of Attacks on Security Protocols
Independent thesis Advanced level (degree of Master (Two Years))Student thesis
Abstract. Security and privacy in digital communications is the need of the hour. SSL/TLS has become widely adopted to provide the same. Multiple application layer protocols can be layered on top of it. However protection is this form results in all the data being encrypted causing problems for an intrusion detection system which relies on a sniffer that analyses packets on a network. We thus hypothesise that a host based intrusion detection system that analyses packets after decryption would be able to detect attacks against security protocols. To this effect we conduct two experiments where we attack a web server and a mail server, collect data, analyse it and conclude with methods to detect such attacks. These methods are in the form of peudocode.
Place, publisher, year, edition, pages
2010. , 25 p.
Timing attack, SSL, TLS, Intrusion Detection, Anomaly based
IdentifiersURN: urn:nbn:se:bth-4806Local ID: oai:bth.se:arkivex4DC4EDA30AD274F6C12577CE003A8304OAI: oai:DiVA.org:bth-4806DiVA: diva2:832154