首页> 外文学位 >On the application of locality to network intrusion detection: Working-set analysis of real and synthetic network server traffic.
【24h】

On the application of locality to network intrusion detection: Working-set analysis of real and synthetic network server traffic.

机译:关于本地性在网络入侵检测中的应用:真实和综合网络服务器流量的工作集分析。

获取原文
获取原文并翻译 | 示例

摘要

Keeping computer networks safe from attack requires ever-increasing vigilance. Our work on applying locality to network intrusion detection is presented in this dissertation. Network servers that allow connections from both the internal network and the Internet are vulnerable to attack from all sides. Analysis of the behavior of incoming connections for properties of locality can be used to create a normal profile for such network servers. Intrusions can then be detected due to their abnormal behavior. Data was collected from a typical network server both under normal conditions and under specific attacks. Experiments show that connections to the server do in fact exhibit locality, and attacks on the server can be detected through their violation of locality.Key to the detection of locality is a data structure called a working-set, which is a kind of cache of certain data related to network connections. Under real network conditions, we have demonstrated that the working-set behaves in a manner consistent with locality. Determining the reasons for this behavior is our next goal. A model that generates synthetic traffic based on actual network traffic allows us to study basic traffic characteristics. Simulation of working-set processing of the synthetic traffic shows that it behaves much like actual traffic. Attacks inserted into a replay of the synthetic traffic produce working-set responses similar to those produced in actual traffic. In the future, our model can be used to further the development of intrusion detection strategies.
机译:要使计算机网络免受攻击,就需要不断提高警惕。本文介绍了将局部性应用于网络入侵检测的工作。允许来自内部网络和Internet的连接的网络服务器很容易受到来自各个方面的攻击。对于本地属性的传入连接行为的分析可用于为此类网络服务器创建常规配置文件。然后,由于其异常行为,可以检测到入侵。在正常情况下和特定攻击下均从典型的网络服务器收集数据。实验表明,与服务器的连接实际上具有局域性,并且可以通过违反局域性来检测对服务器的攻击。局域性检测的关键是一个称为工作集的数据结构,这是一种缓存与网络连接有关的某些数据。在真实的网络条件下,我们已经证明工作集的行为方式与本地性一致。确定此行为的原因是我们的下一个目标。基于实际网络流量生成综合流量的模型使我们能够研究基本流量特征。对合成流量的工作集处理进行的仿真显示,它的行为与实际流量非常相似。插入合成流量重放中的攻击产生的工作集响应与实际流量中产生的响应类似。将来,我们的模型可用于进一步发展入侵检测策略。

著录项

  • 作者

    Lee, Robert.;

  • 作者单位

    University of Central Florida.;

  • 授予单位 University of Central Florida.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2009
  • 页码 131 p.
  • 总页数 131
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号