From Intention to Practice: Towards Systematic Validation of NIDS Rule Enforcement
Huan Liu, Haoyu Chen, Biang Xu, Jingyao Zhou, Bin Yuan, Qiankun Zhang, Deqing Zou, Hai Jin
Abstract
Rule-based Network Intrusion Detection Systems (NIDS) are integral to contemporary cybersecurity, relying on the rule matching mechanism to identify malicious activities within network traffic. However, there is no inherent assurance that the deployed rules are enforced as intended due to factors regarding the composition of the rules and implementation flaws of NIDS. Unfortunately, administrators lack appropriate means to validate the gap between rule definition and enforcement as existing testing approaches towards NIDS are often rule irrelevant and lack systematic methodologies. To address this issue, this paper presents NIDSFUZZ, a systematic fuzzing approach designed to validate the enforcement of rules within NIDS, which is rule-oriented so that it employs tailored mutation strategies to generate test traffic based on the very ruleset deployed. In this manner, it becomes feasible to validate the targeted rulesets with guarantee of coverage. An NIDS-specific fuzzing framework is proposed, incorporating an appropriate test traffic injection method to perform fuzzing and carefully designed approaches of sanitization and analysis to effectively identify rule enforcement issues. Experimental results show that NIDSFUZZ is able to uncover over 10,000 rule enforcement issues. We classified the discovered issues into different categories and explored corresponding countermeasures in terms of both rules and NIDS implementation. Moreover, performance evaluation confirms the efficiency of NIDSFUZZ and comparison to other tools highlights the significant advantage of NIDSFUZZ in evaluating rules of NIDS. We have made our code publicly available.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 39b6602d-3f26-4c64-9077-fd11cff919e0Builds on11
- SlowFuzz: Automated Domain-Independent Detection of Algorithmic Complexity VulnerabilitiesTheofilos Petsios, Jason Zhao, Angelos D. Keromytis, Suman JanaCCS 2017 · 214 citations
- Automatic Root Cause Analysis via Large Language Models for Cloud IncidentsYinfang Chen, Huaibing Xie, Minghua Ma, Yu Kang et al.EuroSys 2024 · 175 citations
- TCP-Fuzz: Detecting Memory and Semantic Bugs in TCP Stacks with FuzzingYonghao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan et al.USENIX ATC 2021 · 53 citations
- Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application FirewallsQi Wang, Jianjun Chen, Zheyu Jiang, Run Guo et al.S&P 2024 · 11 citations
- Towards Understanding the Effectiveness of Large Language Models on Directed Test Input GenerationZongze Jiang, Ming Wen, Jialun Cao, Xuanhua Shi et al.ASE 2024 · 8 citations
Related papers
- Systematically Detecting Packet Validation Vulnerabilities in Embedded Network StacksPaschal C. Amusuo, Ricardo Andrés Calvo Méndez, Zhongwei Xu, Aravind Machiry et al.ASE 2023 · 9 citations
- DELTA: A Security Assessment Framework for Software-Defined NetworksSeungsoo Lee, Changhoon Yoon, Chanhee Lee, Seungwon Shin et al.NDSS 2017 · 128 citations
- SemFuzz: A Semantics-Aware Fuzzing Framework for Network Protocol ImplementationsYanbang Sun, Quan Luo, Yuelin Wang, Qian Chen et al.WWW 2026
- Intender: Fuzzing Intent-Based Networking with Intent-State Transition GuidanceJiwon Kim, Benjamin E. Ujcich, Dave TianUSENIX Security 2023
- AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksSeungsoo Lee, Seungwon Woo, Jinwoo Kim, Vinod Yegneswaran et al.INFOCOM 2020 · 13 citations
