首页> 外文期刊>International Journal of Information Security >A monitoring system for detecting repeated packets with applications to computer worms
【24h】

A monitoring system for detecting repeated packets with applications to computer worms

机译:一种监视重复数据包的监视系统,并应用于计算机蠕虫

获取原文
获取原文并翻译 | 示例
           

摘要

We present a monitoring system which detects repeated packets in network traffic, and has applications including detecting computer worms. It uses Bloom filters with counters. The system analyzes traffic in routers of a network. Our preliminary evaluation of the system involved traffic from our internal lab and a well known historical data set. After appropriate configuration, no false alarms are obtained under these data sets and we expect low false alarm rates are possible in many network environments. We also conduct simulations using real Internet Service Provider topologies with realistic link delays and simulated traffic. These simulations confirm that this approach can detect worms at early stages of propagation. We believe our approach, with minor adaptations, is of independent interest for use in a number of network applications which benefit from detecting repeated packets, beyond detecting worm propagation. These include detecting network anomalies such as dangerous traffic fluctuations, abusive use of certain services, and some distributed denial-of-service attacks.
机译:我们提出了一种监视系统,该系统可检测网络流量中的重复数据包,并具有包括检测计算机蠕虫在内的应用程序。它使用带计数器的Bloom过滤器。系统分析网络路由器中的流量。我们对系统的初步评估涉及内部实验室的流量和众所周知的历史数据集。经过适当的配置后,在这些数据集下不会获得误报,并且我们预计在许多网络环境中误报率都可能较低。我们还使用具有实际链接延迟和模拟流量的真实Internet服务提供商拓扑进行模拟。这些模拟证实了这种方法可以在传播的早期阶段检测蠕虫。我们相信,我们的方法经过细微的修改,对于在许多网络应用程序中使用具有独立的意义,这些网络应用程序不仅可以检测蠕虫传播,还可以从检测重复的数据包中受益。这些措施包括检测网络异常,例如危险的流量波动,滥用某些服务以及某些分布式拒绝服务攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号