首页> 外文会议>Multimedia Information Networking and Security, 2009. MINES '09 >Passive NATted Hosts Detect Algorithm Based on Directed Acyclic Graph Support Vector Machine
【24h】

Passive NATted Hosts Detect Algorithm Based on Directed Acyclic Graph Support Vector Machine

机译:基于有向无环图支持向量机的无源NATted主机检测算法

获取原文

摘要

Unauthorized network address translation (NAT) devices may be a significant security problem. They provide unrestricted access to any number of hosts connecting to them. Some attackers may use computers hidden behind NAT devices to conduct malicious activities such as denial of service. An algorithm is proposed in this work to detect hosts hidden behind NAT. Different from previous researches, the algorithm does not depend on any special field in any packet header. It is based on analyzing traffic features with directed acyclic graph support vector machine (DAGSVM). Firstly, traffic models of hosts are selected from training samples with DAGSVM. Then the models and classifier are used for predicting host number of unknown traces. What revealed by the experiment includes that the proposed algorithm is effective, even when there are more hosts in the test set than it is in the training set, and the accuracy will fall when there are more unknown hosts in the test traces.
机译:未经授权的网络地址转换(NAT)设备可能是一个重大的安全问题。通过它们,可以不受限制地访问连接到它们的任意数量的主机。一些攻击者可能使用隐藏在NAT设备后面的计算机来进行诸如拒绝服务之类的恶意活动。在这项工作中提出了一种算法来检测隐藏在NAT之后的主机。与以前的研究不同,该算法不依赖于任何数据包头中的任何特殊字段。它基于使用有向无环图支持向量机(DAGSVM)分析流量特征的基础。首先,使用DAGSVM从训练样本中选择主机的流量模型。然后使用模型和分类器来预测未知迹线的主机数。实验表明,即使测试集中的主机数量超过训练集中的主机数量,所提出的算法也是有效的;而当测试迹线中的主机数量更多时,准确性也会下降。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号