首页> 外文会议>Computer Security Applications Conference, 2009. ACSAC '09 >Online Sketching of Network Flows for Real-Time Stepping-Stone Detection
【24h】

Online Sketching of Network Flows for Real-Time Stepping-Stone Detection

机译:在线绘制网络流以进行实时步进石检测

获取原文

摘要

We present an efficient and robust stepping-stone detection scheme based on succinct packet-timing sketches of network flows. The proposed scheme employs an online algorithm to continuously maintain short sketches of flows from a stream of captured packets at the network boundary. These sketches are then used to identify pairs of network flows with similar packet-timing characteristics, which indicates potential stepping-stones. Succinct flow sketches enable the proposed scheme to compare a given pair of flows in constant time. In addition, flow sketches identify pairs of correlated flows from a given list of flows in sub-quadratic time, thereby allowing a more scalable solution as compared to known schemes. Finally, the proposed scheme is resistant to random delays and chaff, which are often employed by attackers to evade detection. To explore its efficacy, we mathematically analyze the robustness properties of the proposed flow sketch. We also experimentally measure the detection performance of the proposed scheme.
机译:我们提出了一种基于网络流量的简洁分组定时草图的高效且健壮的踏脚石检测方案。所提出的方案使用在线算法来连续地维护来自网络边界处的捕获分组流的流的简短草图。这些草图随后用于识别具有类似数据包定时特性的网络流对,这表示潜在的垫脚石。简洁的流图使所提出的方案能够在恒定时间内比较给定的一对流。另外,流程草图可在次二次时间内从给定的流程列表中识别成对的相关流程,从而与已知方案相比,可扩展性更高。最后,所提出的方案具有抵抗随机延迟和谷壳的功能,攻击者经常利用这些随机壳和壳来逃避检测。为了探索其功效,我们在数学上分析了所提出的流程草图的鲁棒性。我们还通过实验测量了该方案的检测性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号