首页> 外文会议>Advanced Communication Technology, 2009 11th International Conference on >A case study of unknown attack detection against Zero-day worm in the honeynet environment
【24h】

A case study of unknown attack detection against Zero-day worm in the honeynet environment

机译:蜜网环境中零日蠕虫未知攻击检测案例研究

获取原文

摘要

We have presented an early detection system, ZASMIN (Zero-day Attack Signature Management Infrastructure), for novel network attack protection. This system provides early detection function and validation of attack at the moment the attacks start to spread on the network. In order to detect unknown network attack, the ZASMIN system has adopted various of new technologies, which are composed of suspicious traffic monitoring, attack validation, polymorphic worm recognition, signature generation. Some of these functionalities are implemented with hardware-based accelerator to be able to deal with giga-bit speed traffic, therefore, it can be applicable to Internet backbone or the bottle-neck point of high-speed enterprise network without any loss of traffic. In order to check the feasibility of ZASMIN, we have installed it on real honeynet environment, then we have analyzed the result about detection of unknown attack.
机译:我们提出了一种用于新型网络攻击防护的早期检测系统ZASMIN(零日攻击特征管理基础结构)。当攻击开始在网络上传播时,此系统提供早期检测功能和攻击验证。为了检测未知的网络攻击,ZASMIN系统采用了各种新技术,包括可疑流量监控,攻击验证,多态蠕虫识别和签名生成。这些功能中的某些功能是通过基于硬件的加速器实现的,能够处理千兆位速度的流量,因此,它可以适用于Internet骨干网或高速企业网络的瓶颈点,而不会造成任何流量损失。为了检查ZASMIN的可行性,我们将其安装在实际的蜜网环境中,然后分析了未知攻击的检测结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号