Register for Network Security-Vegas by Sept. 3 for $250 discount. >> More Info
the most trusted source for computer security training, certification and research


Assumptions in Intrusion Detection - Blind Spots in Analysis

Core_1
Abstract
This paper examines one of the common assumptions made as an intrusion analyst looking at network packet captures and explores the possible avenues which could determine that the assumption may not be as trustworthy as has been previously assumed. This paper attempts to guide the analyst by providing a detailed analysis of the TCP/IP standards stack with particular focus on the communication that exists between layers of the stack. As will be shown in this paper, the communication, or lack of communication, provide the possibility of exploitation at various levels as data passes between layers in the standards stack
<<Reading Room Home     <<Back to Category

Contact us: (301) 654-SANS(7267)
Monday - Friday 9am-8pm EST/EDT