Themis: Ambiguity-Aware Network Intrusion Detection based on Symbolic Model Comparison
Zhongjie Wang, Shitong Zhu, Keyu Man, Pengxiong Zhu, Yu Hao, Zhiyun Qian, Srikanth V. Krishnamurthy, Tom La Porta, Michael J. De Lucia
Abstract
Network intrusion detection systems (NIDS) can be evaded by carefully crafted packets that exploit implementation-level discrepancies between how they are processed on the NIDS and at the endhosts. These discrepancies arise due to the plethora of endhost implementations and evolutions thereof. It is prohibitive to proactively employ a large set of implementations at the NIDS and check incoming packets against all of those. Hence, NIDS typically choose simplified implementations that attempt to approximate and generalize across the different endhost implementations. Unfortunately, this solution is fundamentally flawed since such approximations are bound to have discrepancies with some endhost implementations. In this paper, we develop a lightweight system Themis, which empowers the NIDS in identifying these discrepancies and reactively forking its connection states when any packets with "ambiguities" are encountered. Specifically, Themis incorporates an offline phase in which it extracts models from various popular implementations using symbolic execution. During runtime, it maintains a nondeterministic finite automaton to keep track of the states for each possible implementation. Our extensive evaluations show that Themis is extremely effective and can detect all evasion attacks known to date, while consuming extremely low overhead. En route, we also discovered multiple previously unknown discrepancies that can be exploited to bypass current NIDS.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 25583e66-38ca-449c-b62f-2ac6d08ba3e8Cited by top-tier papers3
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan et al.USENIX Security 2024 · 13 citations
- Automata-Based Automated Detection of State Machine Bugs in Protocol ImplementationsPaul Fiterau-Brostean, Bengt Jonsson, Konstantinos Sagonas, Fredrik TåquistNDSS 2023
- SCAD: Towards a Universal and Automated Network Side-Channel Vulnerability DetectionKeyu Man, Zhongjie Wang, Yu Hao, Shenghan Zheng et al.S&P 2025
Builds on9
- NEZHA: Efficient Domain-Independent Differential TestingTheofilos Petsios, Adrian Tang, Salvatore J. Stolfo, Angelos D. Keromytis et al.S&P 2017 · 132 citations
- SymCerts: Practical Symbolic Execution for Exposing Noncompliance in X.509 Certificate Validation ImplementationsSze Yiu Chau, Omar Chowdhury, Md. Endadul Hoque, Huangyi Ge et al.S&P 2017 · 67 citations
- Extract Me If You Can: Abusing PDF Parsers in Malware DetectorsCurtis Carmony, Xunchao Hu, Heng Yin, Abhishek Vasisht Bhaskar et al.NDSS 2016 · 61 citations
- Geneva: Evolving Censorship Evasion StrategiesKevin Bock, George Hughey, Xiao Qiang, Dave LevinCCS 2019 · 60 citations
- Host of Troubles: Multiple Host Ambiguities in HTTP ImplementationsJianjun Chen, Jian Jiang, Hai-Xin Duan, Nicholas Weaver et al.CCS 2016 · 49 citations
Related papers
- SymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy DiscoveryZhongjie Wang, Shitong Zhu, Yue Cao, Zhiyun Qian et al.NDSS 2020
- You Cannot Escape Me: Detecting Evasions of SIEM Rules in Enterprise NetworksRafael Uetz, Marco Herzog, Louis Hackländer, Simon Schwarz et al.USENIX Security 2024 · 23 citations
- A First-Principles Evaluation of Graph-Based Network Intrusion Detection SystemsRui Zhao, Wajih UI HassanCCS 2026
- DiffuPac: Contextual Mimicry in Adversarial Packets Generation via Diffusion ModelAbdullah Bin Jasni, Akiko Manada, Kohei WatabeNeurIPS 2024 · 11 citations
- Genos: General In-Network Unsupervised Intrusion Detection by Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao et al.INFOCOM 2024 · 11 citations
