Skip to main content

Packet Level Normalisation

This paper proposes that any Signature Based Passive Network Intrusion Detection (NID) deployment is incomplete without an 'In-line' 'Packet Level Normaliser' [1]. A number of published papers will be selectively reviewed, assessing their contribution to the development of this field. Focusing on the Network Layer, a 'walkthrough' of the IP protocol will be followed by a Lab where the Normaliser 'norm' [2] will be employed to illustrate core concepts. Packets will be manufactured using 'NetDuDe' [3] and 'Fragroute' [4]. The output will be in 'tcpdump' [5] format. The paper culminates with a brief review of current normaliser technology.

1128 (PDF, 1.76MB)

29 Jul 2003
ByIan Martin
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.