首页> 外文会议>IEEE International Conference on Network Protocols >Forensic Analysis for Epidemic Attacks in Federated Networks
【24h】

Forensic Analysis for Epidemic Attacks in Federated Networks

机译:联邦网络中疫情攻击的法医分析

获取原文

摘要

We present the design of a Network Forensic Alliance (NFA), to allow multiple administrative domains (ADs) to jointly locate the origin of epidemic spreading attacks. ADs in the NFA collaborate in a distributed protocol for post-mortem analysis of worm-like attacks. Information exchange between any two participating ADs is limited to traffic records that are known to both sides, maintaining the privacy of participants. Such an architecture is incentive-compatible - participants benefit by gaining better local investigative capabilities, even with partial deployment. Further, we show that by sharing local investigation results, ADs can achieve global investigative capabilities that are comparable to a centralized implementation with access to global traffic records. Our evaluation demonstrates that it is feasible for large-scale attack investigation to be incrementally deployed in an Internet-like federation.
机译:我们介绍了网络取证联盟(NFA)的设计,以允许多个管理域名(广告)共同定位流行病传播攻击的起源。 NFA中的广告在分布式协议中协作,用于蠕虫的攻击后验尸分析。任何两个参与广告之间的信息交换都仅限于双方所知的交通记录,维护参与者的隐私。这种架构是兼容的 - 参与者通过获得更好的当地调查能力,即使是部分部署也是如此。此外,我们表明,通过分享本地调查结果,广告可以实现与集中实施相当的全球调查能力,可以访问全球流量记录。我们的评估表明,在类似于互联网的联合中逐步部署的大规模攻击调查是可行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号