首页> 外文会议>Computer Science and Software Engineering, CSSE 2008, 2008 International Conference on >An Approach on Detecting Attack Based on Causality in Network Behavior
【24h】

An Approach on Detecting Attack Based on Causality in Network Behavior

机译:一种基于因果关系的网络行为攻击检测方法

获取原文

摘要

An SNMP MIB oriented approach based on two-tier GCT is presented in this paper in order to detect attack before the security of target was damaged. According to the abnormal behavior constructed on target, GCT is executed first to find preliminary attacking variables which has whole causality with abnormal variable in network behavior. Depending on behavior features extracted from abnormal behavior, GCT is executed again to recognize attacking variable which has local causality with abnormal variable in local behavior. The causality between attacking and abnormal variable is used to build rules, with which attack can be detected on attacker. udpOutDatagrams was recognized as attacking variable successfully and detecting results was obtained well in experiment where Trin00 UDP Flood was selected to attack. The final results showed that the approach with two-tier GCT was proved to detect attack early, which has great effect on blocking the pervasion of attacking procedure to target.
机译:提出了一种基于两层GCT的面向SNMP MIB的方法,以在目标安全性受损之前检测攻击。根据目标上构造的异常行为,首先执行GCT,以找到具有整体因果关系且网络行为具有异常变量的初步攻击变量。根据从异常行为中提取的行为特征,再次执行GCT以识别具有局部因果关系且局部行为异常的攻击变量。攻击变量与异常变量之间的因果关系用于建立规则,从而可以检测到攻击者的攻击。在选择Trin00 UDP Flood进行攻击的实验中,udpOutDatagrams被成功识别为攻击变量,并获得了很好的检测结果。最终结果表明,采用两层GCT的方法被证明可以尽早发现攻击,这对于阻止攻击程序向目标的泛滥具有很大的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号