HCMC NATIONAL UNIVERSITY UNIVERSITY OF TECHNOLOGY -------------------- TRẦN HUY VŨ RESEARCH AND IMPLEMENT A PREPROCESSOR FOR NETWORK INTRUSION DETECTION SYSEM NIDS Major: Computer Science. Major ID: 604801……………… GRADUATE THESIS HO CHI MINH CITY - December, 2011 CÔNG TRÌNH ĐƯỢC HOÀN THÀNH TẠI TRƯỜNG ĐẠI HỌC BÁCH KHOA –ĐHQG -HCM Cán bộ hướng dẫn khoa học : TS. Trần Ngọc Thịnh. (Ghi rõ họ, tên, học hàm, học vị và chữ ký) Cán bộ chấm nhận xét 1 : TS.
Đinh Đức Anh Vũ. (Ghi rõ họ, tên, học hàm, học vị và chữ ký) Cán bộ chấm nhận xét 2 : TS. Trần Mạnh Hà. (Ghi rõ họ, tên, học hàm, học vị và chữ ký) Luận văn thạc sĩ được bảo vệ tại Trường Đại học Bách Khoa, ĐHQG Tp.
Thành phần Hội đồng đánh giá luận văn thạc sĩ gồm: (Ghi rõ họ, tên, học hàm, học vị của Hội đồng chấm bảo vệ luận văn thạc sĩ) 1. Trần Ngọc Thịnh. Đinh Đức Anh Vũ. Trần Mạnh Hà.
Xác nhận của Chủ tịch Hội đồng đánh giá LV và Trưởng Khoa quản lý chuyên ngành sau khi luận văn đã được sửa chữa (nếu có). CHỦ TỊCH HỘI ĐỒNG KHOA QUẢN LÝ CHUYÊN NGÀNH TS. Trần Văn Hoài TS. Đinh Đức Anh Vũ ĐẠI HỌC QUỐC GIA TP.HCM CỘNG HÒA XÃ HỘI CHỦ NGHĨA VIỆT NAM TRƯỜNG ĐẠI HỌC BÁCH KHOA Độc lập - Tự do - Hạnh phúc NHIỆM VỤ LUẬN VĂN THẠC SĨ Họ tên học viên: Trần Huy Vũ.
Ngày, tháng, năm sinh: 09/12/1896. Nơi sinh: Đồng Nai. Chuyên ngành: Khoa Học Máy Tính. TÊN ĐỀ TÀI: Nghiên cứu và hiện thực bộ tiền xử lí cho hệ thống phát hiện xâm nhập NIDS.
NHIỆM VỤ VÀ NỘI DUNG:. - Tìm hiểu bộ tiền xử lí của các hệ thống phát hiện xâm nhập mạng NIDS hiện có trên thế giới ……………. - Đề xuất giải pháp cải tiến cho bộ tiền xử lí. - Lựa chon platform để hiện thực bộ tiền xử lí, kiểm nghiệm hệ thống.
NGÀY GIAO NHIỆM VỤ :…04/07/2011. NGÀY HOÀN THÀNH NHIỆM VỤ: …06/01/2012. CÁN BỘ HƯỚNG DẪN : …TS. Trần Ngọc Thịnh.
HCM, ngày 05 tháng 12 năm 2011 CÁN BỘ HƯỚNG DẪN KHOA QUẢN LÝ CHUYÊN NGÀNH (Họ tên và chữ ký) (Họ tên và chữ ký) TS. Trần Ngọc Thịnh TS. Đinh Đức Anh Vũ Ghi chú: Học viên phải đóng tờ nhiệm vụ này vào trang đầu tiên của tập thuyết minh LV I ACKNOWLEDGEMENT Foremost, I would like to thank my advisor Dr. Tran Ngoc Thinh, Head of Department of Computer Engineering, Faculty of Computer Science and Engineering, Ho Chi Minh city University of Technology.
His encouragement and his guidance is the motivation for me to proceed my thesis. I greatly appreciate his comments on this thesis as well as on my conference papers. I would also like to thank the Computer Engineering graduate committee for the comments. They offer me many ideas to improve my work in the future.
They also provided me a chance to prove myself capable. Finally, I would like to thank my family members and friends for their supports and encouragements. Tran Huy Vu Author: Tran Huy Vu II TÓM TẮT LUẬN VĂN Ngày nay, hệ thống mạng đóng một vai trò rất quan trọng trong mọi lĩnh vực. Chính sự quan trọng của hệ thống mạng làm cho nó trở nên một trong những thành phần dễ bị tổn hại nhất.
Để khắc phục nhược điểm trên, các Hệ Thống Phát Hiện Xâm Nhập Mạng đã được giới thiệu. Khi các hệ thống này, nhất là các hệ thống NIDS bằng phần cứng, xử lí các gói tin TCP, chúng đều cần một bộ Tiền Xử Lí để lắp ghép các dòng TCP nhằm làm tăng sức mạnh cho các hệ thống NIDS này. Trong luận văn này, chúng tôi đề xuất một phương pháp lai để hiện thực một bộ Tiền Xử Lí cho NIDS. Hệ thống trong luận văn này không chỉ hỗ trợ hang trăm ngàn kết nối đồng thời với những kết nối đứt đoạn, mà còn sử dụng bộ nhớ hiệu quả hơn những hệ thống trước đó.
Kết quả thực nghiệm cho thấy hệ thống này hỗ trợ lên tới 256 ngàn kết nối đồng thời, và khoảng 46 ngàn các kết nối đứt đoạn chỉ với 64MB DRAM. Hệ thống cũng hỗ trợ các NIDS pháp hiện các mẫu tấn công rải trên nhiều gói. Author: Tran Huy Vu III ABSTRACT Nowadays, networking plays a very important role in every fields of life. The importance of the network also makes it a vulnerable part of many organizations.
To overcome this weak point, Network Intrusion Detection Systems (NIDS) are introduced. When these NIDSes, especially hardware NIDS, process packets of Transmission Control Protocol (TCP), they need a preprocessor to reassemble discrete TCP packets in a flow to strengthen the NIDS. In this thesis, we propose a hybrid method to implement a preprocessor for an NIDS. Our system not only supports thousands of TCP connections with multiple out-of-sequence data segments but also uses memory more efficiently than other systems.
The experimental results show that our system can hold about 256K connections simultaneously and support up to 46K out-of-sequence connections with only 64MB DRAM. This system also supports NIDSs to detect attack patterns which expand over packets. Author: Tran Huy Vu IV COMMITMENT I commit that this thesis is made based on my own research. I do not copy or use any illegal material in this thesis.
All reference of this thesis are cited from public resource or in permission of the authors/publisher I am directly responsible for any contradiction with the content of this thesis Tran Huy Vu Author: Tran Huy Vu V Table of Contents ACKNOWLEDGEMENT .IV LIST OF FIGURES. VIII LIST OF TABLES.XI Chapter 1 Introduction .2 Statement of problem .1 Transmission Control Protocol .1 TCP/IP model .2 Flow control mechanism .3 Three way hand shaking .1 TCP packets re-ordering .2 TCP flow reassembly .3 Network intrusion detection system. - 13 - Author: Tran Huy Vu VI 2.2 NIDS project at Faculty of Computer Science and Engineering HCMUT .2 Design with the reference design. - 17 - Chapter 3 Related works .1 The TCP processor [4].2 Out-of-order TCP stream scanning [3] .3 Robust TCP reassembly for backbone traffic [1] .4 TCP reassembly for Sachet IDS [5] .5 Robust TCP stream reassembly of Sarang Dharmapurikar and Vern Paxson [2] - 20 - Chapter 4 Method of TCP reassembly .1 Method for re-ordering TCP packets .1 The data structure .2 Operation on reassembly memory .2 Method for reassembling TCP flow.
- 31 - Chapter 5 System implementation .1 The Input Controller module .2 The Packet Manager module .3 The Flow Controller module.4 The Reassembler module. - 37 - Author: Tran Huy Vu VII 5.5 The Memory controller module .6 The Output controller module. - 39 - Chapter 6 Evaluation of the TCP Reassemble Engine .4 Capability of supporting NIDS. - 48 - Chapter 7 Conclusion and future work.
- 51 - Author: Tran Huy Vu VIII LIST OF FIGURES Figure 1-1. Out-of-sequence packets passing an NIDS. - 2 - Figure 1-2 Deployment model of the Preprocessor and NIDS. TCP/IP model and packing data of TCP packet.
IPv4 header format. TCP header format. - 7 - Figure 2-4 the Flow control mechanism. - 8 - Figure 2-5 Three way hand shaking in TCP connection.
- 9 - Figure 2-6 out-of-order TCP packets passing an NIDS. - 10 - Figure 2-7 Five situations of TCP hole filling up. - 10 - Figure 2-8 NIDS and the deployment model. - 11 - Figure 2-9 HIDS and deployment model.
- 12 - Figure 2-10 Architecture of Snort. - 13 - Figure 2-11 The NetFPGA board. - 16 - Figure 4-1 A segment of packet S, packet S+1, packet S+2 in a linked list. - 22 - Figure 4-2 Data structure of reassembly memory with a 4-hole out-of-sequence connection.
- 23 - Figure 4-3 Structure of the segment array. Each element is divided and store at different place. - 24 - Figure 4-4Structure of a memory block. If a packet does not used a whole block, others packets in the same segment can fill in the block.
- 25 - Figure 4-5 Structure of a connection record. - 26 - Figure 4-6Creating of new segment. - 28 - Figure 4-7 Inserting a packet to a segment. - 29 - Figure 4-8 Merging two segments.
- 30 - Figure 4-9 Releasing of e segment array. - 31 - Author: Tran Huy Vu IX Figure 4-10 The original one-edge buffering scheme, l = 6; a) the successive packet arrives, b) the preceded packet arrives. - 32 - Figure 4-11 Modified Two-edge buffering scheme for ordered TCP stream, with l = 5 - 32 - Figure 5-1 Block diagram of the Preprocessor. - 33 - Figure 5-2 The Input controller.
- 33 - Figure 5-3 The Packet manager. - 35 - Figure 5-4 The Flow Controller. - 35 - Figure 5-5 The Reassembler. - 37 - Figure 5-6 The Memory controller.
- 38 - Figure 5-7 The Output controller. - 39 - Figure 6-1 Deployment model of the preprocessor and NIDS. - 40 - Figure 6-3 the incoming paket, rx_ll_data holds the data. - 41 - Figure 6-2 Individual test for the Preprocessor.
- 41 - Figure 6-4 The payload of the output packet is inserted with the last 32 bytes of the previous packet. - 42 - Figure 6-5 Maximum throughput of the system when percentage of out-of-sequence packets is 0%. - 44 - Figure 6-6 Throughput of the system with lcock rate=125MHz when percentage of out- of-sequence packets is 0%. - 45 - Figure 6-7 Maximum throughput of the system when percentage of out-of-sequence packets is 5%.
- 45 - Figure 6-8 Throughput of the system with clock rate = 125MHz when percentage of out-of-sequence packets is 5%. - 46 - Figure 6-9 Maximum throughput of the system when percentage of out-of-sequence packets is 10%. - 46 - Author: Tran Huy Vu X Figure 6-10 Throughput of the system with clock rate = 125MHz when percentage of out-of-sequence packets is 10%. - 47 - Figure 6-11 Number of rules with different length.
- 48 - Author: Tran Huy Vu XI LIST OF TABLES Table 6-1 Percentage of supported connection types of the TCP Reassembly Engine and other systems. - 43 - Table 6-2 Memory utilization of the TCP Reassembly Engine and other systems for single-hole connections only. - 43 - Author: Tran Huy Vu -1- Chapter 1 Introduction 1.1 Motivation Nowadays network is vital to almost every organization. E-Commerce is an instance and it is growing rapidly based on the web infrastructure.
E-Government has been deployed in some countries and continually expanded; and many companies or schools use network to communicate with their staff and customers. Because of such importance of network, the security of the network is a serious issue to be solved. The network can be the most vulnerable part of an organization, and it should be protected from many crimes. Statistics show that the information crime has increased dramatically for recent years, they are widely known as the Cybercrime.
Interpol reports the cost of Cybercrime or Computer crime [9] worldwide reach $ 8 billion in 2007 and 2008. This type of crime always uses a computer and a network [10] to carry out their illegal intrusion or simply to disable a server by DoS (Denial of Service) attack.