首页> 外文会议>International Conference on Information Assurance and Security >Optimization of excerpt query process for Packet Attribution System
【24h】

Optimization of excerpt query process for Packet Attribution System

机译:分组归属系统摘录查询过程的优化

获取原文

摘要

Internet and its applications have increased to an enormous extent in the past decade. As the usage increased, it has also exposed its users to various security threats. Network forensic techniques can be used to traceback the source and the path of an attack that can be used as a legal evidence in a court of law. Packet attribution techniques like Source Path Isolation (SPIE), Block Bloom Filter (BBF), Hierarchical Bloom Filter (HBF) are proposed to store the packet data into the bloom filters at each router present in the network. All the routers in the Autonomous System (AS) are queried for presence of excerpt in their bloom filters to traceback source and path of attack. Upon receiving the excerpt query, each router search their bloom filters for presence of excerpt and send the result to NMS. NMS receives the response from routers and determines the traceback path from victim to source of attack. In this process, all the routers are engaged in searching the bloom filters, causing possible delay in performing actual routing tasks. This degrades network performance and may adversely affect QoS of network. To address potential performance issues, in this paper, we propose query optimization techniques, reducing the number of routers to be searched to a great extent, without adversely affecting storage and processing requirements as compared to existing attribution methods.
机译:在过去的十年中,Internet及其应用已大大增加。随着使用量的增加,它也使用户面临各种安全威胁。网络取证技术可用于追溯攻击的来源和路径,并可用作法院的法律证据。提出了诸如源路径隔离(SPIE),块布隆过滤器(BBF),分层布隆过滤器(HBF)之类的分组归因技术,以将分组数据存储到网络中每个路由器处的布隆过滤器中。询问自治系统(AS)中的所有路由器,是否在其布隆过滤器中找到摘录,以追溯到攻击源和攻击路径。收到摘要查询后,每个路由器都会在其bloom筛选器中搜索摘要的存在并将结果发送到NMS。 NMS从路由器接收响应,并确定从受害者到攻击源的追溯路径。在此过程中,所有路由器都将参与搜索布隆过滤器,从而导致执行实际路由任务时可能出现延迟。这会降低网络性能,并可能对网络的QoS产生不利影响。为了解决潜在的性能问题,在本文中,我们提出了查询优化技术,与现有的归属方法相比,在很大程度上不会减少要搜索的路由器数量,并且不会对存储和处理要求产生不利影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号