首页> 外文会议>Iranian Conference on Electrical Engineering >An efficient sketch-based framework to identify multiple heavy-hitters and its application in DoS detection
【24h】

An efficient sketch-based framework to identify multiple heavy-hitters and its application in DoS detection

机译:一个有效的基于草图的框架,可识别多个重击者及其在DoS检测中的应用

获取原文

摘要

Nowadays, with the increasing speed of communication links and generated traffic volume, Network Intrusion Detection Systems (NIDSs) encounter new challenges. NIDSs inspect all packets to find attacks and abnormal behaviors. In addition, NIDSs keep the state of each flow to increase accuracy of detection. Performing packet inspection in today's high-speed networks is hard, or even impossible and keeping per flow state is not scalable. Large-scale attacks such as DoS attack usually produce many flows and keeping their state requires many resources. Consequently, approaches that investigate behavior of communication patterns in flow-level - instead of packet inspection - are taken into consideration. Different algorithms and techniques have been proposed for flow-based detection of DoS attacks. Recently, approaches based on data streaming algorithms have attracted much attention. These algorithms enable the analysis and processing of large data sets by constructing a compact synopsis of input data. This synopsis can be used to answer certain queries over the original data. Sketch is one of these synopsis structures which different intrusion detection systems are proposed by using it. Most of these proposed approaches have good performance if just one flow has anomalous characteristics. But if there are several abnormal flows, sketches encounter difficulties. This paper for the first time provides a framework to avoid such problems in presence of several abnormal flows. The proposed framework rearranges hash functions in an appropriate data structures and overcomes such problems in presence of several abnormal flows.
机译:如今,随着通信链路速度的提高和所产生的通信量的增加,网络入侵检测系统(NIDS)面临着新的挑战。 NIDS检查所有数据包以发现攻击和异常行为。另外,NIDS保持每个流的状态以提高检测的准确性。在当今的高速网络中执行数据包检查非常困难,甚至是不可能的,并且保持每个流状态不可扩展。诸如DoS攻击之类的大规模攻击通常会产生许多流,并且保持其状态需要大量资源。因此,考虑了在流级别上研究通信模式行为的方法,而不是数据包检查。已经提出了用于基于流的DoS攻击检测的不同算法和技术。近来,基于数据流算法的方法引起了很多关注。这些算法通过构造输入数据的简要提要,可以分析和处理大型数据集。此提要可用于回答对原始数据的某些查询。 Sketch是这些提要结构之一,通过使用它,提出了不同的入侵检测系统。如果仅一种流具有异常特征,则大多数这些提议的方法都具有良好的性能。但是,如果有多个异常流程,则草图会遇到困难。本文首次提供了一个框架,可以避免在出现多个异常流的情况下发生此类问题。所提出的框架在适当的数据结构中重新排列了散列函数,并克服了几种异常流的存在下的此类问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号