English

Evading network-level emulation

Cryptography and Security 2009-06-11 v1

Abstract

Recently more and more attention has been paid to the intrusion detection systems (IDS) which don't rely on signature based detection approach. Such solutions try to increase their defense level by using heuristics detection methods like network-level emulation. This technique allows the intrusion detection systems to stop unknown threats, which normally couldn't be stopped by standard signature detection techniques. In this article author will describe general concepts of network-level emulation technique including its advantages and disadvantages (weak sides) together with providing potential countermeasures against this type of detection method.

Keywords

Cite

@article{arxiv.0906.1963,
  title  = {Evading network-level emulation},
  author = {Piotr Bania},
  journal= {arXiv preprint arXiv:0906.1963},
  year   = {2009}
}

Comments

7 pages

R2 v1 2026-06-21T13:12:02.639Z