Talk With an Expert

Processing experimental protocols against IDS

Processing experimental protocols against IDS (PDF, 4.52MB)Published: 10 Aug, 2018
Created by:
Tommy Adams

Experimental protocols such as TCP Fastopen, QUIC, and Multipath TCP are not uncommon on Internet-connected networks. If a network has modern operating systems and browsers, it is a near certainty that experimental protocols are traversing the network. This paper will examine potential consequences of experimental protocols to current network security monitoring practices and the potential for intrusion detection evasion. This paper will provide a roadmap by which an analyst may process any new, odd, or experimental traffic against their open-source intrusion detection system.