NIDS polymorphic evasion - The End?
July 25, 2005

Today’s Network Intrusion Detection Systems, alarmed of the dangers brought by polymorphic shellcodes, try to detect them using desperate methods that eat up CPU cycles. This is done so the claim can be made that such NIDS foil even the most devious crackers. The truth of the matter is, they don’t.

This paper demonstrates the weaknesses in today’s polymorphism detection methods, and explores techniques to exploit them. The accompanying ECL-Polynop tool can be obtained from here.