【24h】

Signature-Aware Traffic Monitoring with IPFIX

机译:使用IPFIX进行签名感知流量监控

获取原文
获取原文并翻译 | 示例

摘要

Traffic monitoring is essential for accounting user traffic and detecting anomaly traffic such as Internet worms or P2P file sharing applications. Since typical Internet traffic monitoring tools use only TCP/UDP/IP header information, they cannot effectively classify diverse application traffic, because TCP or UDP port numbers could be used by different applications. Moreover, under the recent deployment of firewalls that permits only a few allowed port numbers, P2P or other non-well-known applications could use the well-known port numbers. Hence, a port-based traffic measurement scheme may not provide the correct traffic monitoring results. On the other hand, traffic monitoring has to report not only the general statistics of traffic usage but also anomaly traffic such as exploiting traffic, Internet worms, and P2P traffic. Particularly, the anomaly traffic can be more precisely identified when packet payloads are inspected to find signatures. Regardless of correct packet-level measurement, flow-level measurement is generally preferred because of easy deployment and low-cost operation. In this paper, therefore, we propose a signature-aware flow-level traffic monitoring method based on the IETF IPFIX standard for the next-generation routers, where the flow format of monitoring traffic can be dynamically defined so that signature information could be included. Our experimental results show that the signature-aware traffic monitoring scheme based on IPFIX performs better than the traditional port-based traffic monitoring method. That is, hidden anomaly traffic with the same port number has been revealed.
机译:流量监控对于计算用户流量和检测异常流量(例如Internet蠕虫或P2P文件共享应用程序)至关重要。由于典型的Internet流量监视工具仅使用TCP / UDP / IP标头信息,因此它们无法有效地对各种应用程序流量进行分类,因为TCP或UDP端口号可以由不同的应用程序使用。此外,在防火墙的最新部署中,防火墙仅允许一些允许的端口号,P2P或其他不知名的应用程序可以使用众所周知的端口号。因此,基于端口的流量测量方案可能无法提供正确的流量监控结果。另一方面,流量监控不仅必须报告流量使用情况的常规统计信息,还必须报告异常流量,例如利用流量,Internet蠕虫和P2P流量。特别地,当检查分组有效载荷以找到签名时,可以更精确地识别异常流量。不管正确的数据包级别测量如何,由于易于部署和成本低廉,通常首选流量级别测量。因此,在本文中,我们针对下一代路由器提出了一种基于IETF IPFIX标准的可识别签名的流量级流量监控方法,该方法可以动态定义监控流量的流量格式,从而可以包括签名信息。我们的实验结果表明,基于IPFIX的签名感知流量监控方案的性能要优于传统的基于端口的流量监控方法。也就是说,已经揭示了具有相同端口号的隐藏异常流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号