首页> 外文会议>2011 IEEE International Conference on Communications >An Accurate Sampling Scheme for Detecting SYN Flooding Attacks and Portscans
【24h】

An Accurate Sampling Scheme for Detecting SYN Flooding Attacks and Portscans

机译:一种用于检测SYN Flood攻击和Portscans的精确采样方案

获取原文

摘要

In this paper, we propose an accurate sampling scheme for defeating SYN flooding attacks as well as TCP portscan activity. The scheme examines TCP segments to find at least one of multiple ACK segments coming from the server. The method is simple and scalable, because it achieves good detection performance with false positive rate close to zero even for very low sampling rates. Our trace-based simulations show that the effectiveness of the proposed scheme only relies on the sampling rate regardless on the sampling method.
机译:在本文中,我们提出了一种用于克服SYN泛洪攻击以及TCP portcan活动的准确采样方案。该方案检查TCP段,以找到来自服务器的多个ACK段中的至少一个。该方法简单且可扩展,因为即使在非常低的采样率下,其假阳性率也接近零,从而实现了良好的检测性能。我们基于跟踪的仿真表明,所提方案的有效性仅取决于采样率,而与采样方法无关。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号