首页> 外文会议>International conference on Information security >A real-time algorithm to detect long connection chains of interactive terminal sessions
【24h】

A real-time algorithm to detect long connection chains of interactive terminal sessions

机译:一种实时算法,用于检测交互式终端会话的长连接链

获取原文

摘要

Most computer intruders usually chain many computers so as to hide themselves before launching an attack on a target computer. One way to stop such attacks is to prevent the hackers from using computers as stepping-stones for their attack. In this paper, we propose an algorithm to detect the length of the connection chain. By monitoring packets of outgoing and incoming connections, we are able to compute the roundtrip time gap between a client's "request" and the server's "reply." From the changes in the gaps, we can estimate the number of hosts from the current machine to the destination machine. Our algorithm has two advantages compare to the previous results [3]: (1) the estimation of the connection chain is more accurate, and (2) the algorithm can be used in real-time to detect long connection chains.
机译:大多数计算机入侵者通常会链接许多计算机,以便在对目标计算机发起攻击之前将其隐藏起来。阻止此类攻击的一种方法是防止黑客将计算机用作攻击的垫脚石。在本文中,我们提出了一种检测连接链长度的算法。通过监视传出和传入连接的数据包,我们能够计算出客户端的“请求”与服务器的“答复”之间的往返时间间隔。根据差距的变化,我们可以估计从当前计算机到目标计算机的主机数量。与先前的结果[3]相比,我们的算法有两个优点:(1)连接链的估计更加准确;(2)该算法可以实时用于检测长连接链。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号