错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Header Modification Attack Against Intrusion Detection Systems

  • Kyle Thompson,
  • Everett Lee Conway,
  • Dongfeng (Phoenix) Fang

摘要

Network Intrusion Detection Systems (IDSs) have been popular for more than two decades. There has been growing interest in using machine learning techniques for network intrusion detection. However, machine learning models are known to be susceptible to adversarial examples. We demonstrate that this weakness persists when machine learning models are used in IDSs. Specifically, we craft an attack under white box assumptions against two recently proposed machine learning-based IDSs and show that just by adding no-op bytes to IPv4 packet headers, we can decrease the area under the IDS’s ROC curve by up to 18 units.