首页> 外文会议>ACM workshop on Rapid malcode >Scalable internet threat monitoring
【24h】

Scalable internet threat monitoring

机译:可扩展的互联网威胁监控

获取原文

摘要

In the time is takes to read this sentence, the Slammer worm was able to probe over a hundred million Internet hosts. Worse, this attack was both trivial and unsophisticated. Indeed, the ability to easily compromise tens of thousands of Internet hosts has emerged as the backbone of a criminal economy that includes SPAM, denial-of-service extortion, phishing, piracy and on-line identity theft. Keeping up with such prodigious speed and such broad reach continues to present new challenges for network monitoring and defense. This talk focuses on these scaling challenges in the context of two concrete systems: Earlybird - a line-rate system for automatically inferring signatures for new network worms in seconds, and Potemkin - a high-fidelity honeyfarm system designed to efficiently scale to millions of live hosts.
机译:在花时间阅读这句话时,Slammer蠕虫能够探测超过一亿个Internet主机。更糟糕的是,这种攻击既琐碎又简单。确实,轻松危害成千上万个Internet主机的能力已成为包括SPAM,拒绝服务勒索,网络钓鱼,盗版和在线身份盗窃在内的犯罪经济的支柱。跟上如此惊人的速度和如此广泛的覆盖范围,继续为网络监控和防御提出了新的挑战。本演讲将重点讨论两个具体系统中的扩展挑战:Earlybird(一种线速系统,可在几秒钟内自动推断出新网络蠕虫的签名)和Potemkin(一种高保真蜜农场系统),旨在有效地扩展到数百万个活生生的系统。主机。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号