首页> 外文会议>ICC;IEEE International Conference on Communications >A mark association-based investigation of attack scenarios in communication networks
【24h】

A mark association-based investigation of attack scenarios in communication networks

机译:基于标记关联的通信网络攻击场景调查

获取原文

摘要

The tracing of attacks and the reconstruction of attack scenarios are among the research fields that have been investigated these last years. In this context, several marking techniques have been proposed to traceback the attacker IP address or network. These schemes have shown limitations when dealing with the investigation of attacks since they are unable to reconstruct the attacker actions, and tolerate any form of missing traces or marks. In addition, these schemes are vulnerable to mark spoofing and altering. To deal with these limitations, we propose in this paper an outbound global marking scheme which uses a novel structure, called mark association, that holds enriched information about the intruder activity either at the network, system or storage level. The proposed scheme enables the monitoring of the intruder activity, the tracking of occurred events, the traceback of the attackers source addresses, in addition to the reconstruction of attack scenarios. The capabilities of the proposed scheme are illustrated through a distributed attack performed against the monitored environment.
机译:攻击的跟踪和攻击场景的重建是最近几年研究的领域。在这种情况下,已经提出了几种标记技术来追溯攻击者的IP地址或网络。这些方案在处理攻击调查时显示出局限性,因为它们无法重建攻击者的行为,并且无法容忍任何形式的丢失痕迹或标记。另外,这些方案容易受到标记欺骗和篡改的影响。为了解决这些限制,我们在本文中提出了一种出站全局标记方案,该方案使用一种称为标记关联的新颖结构,该结构可以在网络,系统或存储级别上保存有关入侵者活动的丰富信息。所提出的方案不仅可以重建攻击方案,还可以监视入侵者的活动,跟踪发生的事件,追溯攻击者的源地址。通过针对受监控环境执行的分布式攻击来说明所提出方案的功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号