首页> 外文会议> >Detecting disruptive routers: a distributed network monitoring approach
【24h】

Detecting disruptive routers: a distributed network monitoring approach

机译:检测破坏性路由器:分布式网络监视方法

获取原文

摘要

An attractive target for a computer system attacker is the router. An attacker in control of a router can disrupt communication by dropping or misrouting packets passing through the router. We present a protocol called WATCHERS that detects and reacts to routers that drop or misroute packets. WATCHERS is based on the principle of conservation of flow in a network: all data bytes sent into a node, and not destined for that node, are expected to exit the node. WATCHERS tracks this flow, and detects routers that violate the conservation principle. We show that WATCHERS has several advantages over existing network monitoring techniques. We argue that WATCHERS' impact on router performance and WATCHERS' memory requirements are reasonable for many environments. We demonstrate that in ideal conditions WATCHERS makes no false-positive diagnoses. We also describe how WATCHERS can be tuned to perform nearly as well in realistic conditions.
机译:路由器是计算机系统攻击者的诱人目标。控制路由器的攻击者可以通过丢弃或错误路由通过路由器的数据包来破坏通信。我们提出了一种称为WATCHERS的协议,该协议可检测丢弃或错误路由数据包的路由器并对其做出反应。 WATCHERS基于保护网络中流量的原理:发送到节点而不是发往该节点的所有数据字节均应退出该节点。 WATCHERS跟踪此流,并检测违反保护原则的路由器。我们证明了WATCHERS与现有的网络监控技术相比具有多个优势。我们认为WATCHERS对路由器性能的影响和WATCHERS的内存要求在许多环境中都是合理的。我们证明,在理想条件下,WATCHERS不会做出任何假阳性诊断。我们还描述了如何调整WATCHERS在现实条件下的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号