首页> 外文会议>Distributed Computing Systems Workshops, 2009. ICDCS Workshops '09 >An Attack-Resilent Sampling Mechanism for Integrated IP Flow Monitors
【24h】

An Attack-Resilent Sampling Mechanism for Integrated IP Flow Monitors

机译:集成IP流监视器的防攻击采样机制

获取原文

摘要

This paper introduces an adaptive packet sampling mechanism for IP flow monitors that are incorporated into network elements. Such monitors have limited resources that can be rapidly exhausted by network attacks such as distributed denial-of-service (DDoS) and port scanning. The mechanism provides resilience against these types of network attacks by adapting its packet sampling rate according to the available resources in the monitor, and on the flow statistics. Results are presented that show how the sampling mechanism is able to constrain the number of flow entries to available memory resources and how it meets a key criterion of IP flow monitoring systems under duress, whereby the monitoring performance degrades gracefully during attack periods.
机译:本文介绍了一种适用于IP流监视器的自适应数据包采样机制,该机制已集成到网络元素中。此类监视器的资源有限,可以通过网络攻击(例如分布式拒绝服务(DDoS)和端口扫描)迅速耗尽。该机制通过根据监视器中的可用资源和流量统计信息调整其数据包采样率,从而提供了针对这些类型网络攻击的弹性。结果表明,采样机制如何将流条目的数量限制为可用的内存资源,以及如何满足处于压力下的IP流监视系统的关键标准,从而在攻击期间监视性能会下降。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号