首页> 外文会议>IEEE Symposium on Security and Privacy >Detecting Disruptive Routers: A Distributed Network Monitoring Approach
【24h】

Detecting Disruptive Routers: A Distributed Network Monitoring Approach

机译:检测破坏性路由器:分布式网络监控方法

获取原文

摘要

An attractive target for a computer system attacker is the router. An attacker in control of a router can disrupt communication by dropping or misrouting packets passing through the router. We present a protocol called WATCHERS that detects and reacts to routers that drop or misroute packets. WATCHERS is based on the principle of conservation of flow in a network: all data bytes sent into a node, and not destined fro that node, are expected to exit the node. WATCHERS tracks this flow, and detects routers that violate the conservation principle. We show that WATCHERS has several advantages over existing network monitoring techniques. We argue that WATCHERS' impact on router performance and WATCHERS' memory requirements are reasonable for many environments. We demonstrate that in ideal conditions WATCHERS makes no false-positive diagnoses. We also describe how WATCHERS can be tuned to perform nearly as well in realistic conditions.
机译:计算机系统攻击者的有吸引力的目标是路由器。控制路由器中的攻击者可以通过丢弃或错误传递通过路由器的数据包来扰乱通信。我们提出了一个名为Datainers的协议,该协议检测和对丢弃或错误数据包的路由器进行反应。观察者基于网络中的流量保护原理:预计将发送到节点中的所有数据字节,而不是该节点的注定来源。观察者跟踪这种流程,并检测违反保护原理的路由器。我们表明观察者对现有网络监控技术具有几个优点。我们认为观察者对路由器性能和观察者的内存要求的影响是合理的许多环境。我们证明,在理想的条件下,观察者没有假阳性诊断。我们还描述了观察者如何在现实条件下调整到几乎表现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号