首页> 外文会议>Integrated Network Management, 2003. IFIP/IEEE Eighth International Symposium on >Proactive intrusion detection and SNMP-based security management: new experiments and validation
【24h】

Proactive intrusion detection and SNMP-based security management: new experiments and validation

机译:主动入侵检测和基于SNMP的安全管理:新实验和验证

获取原文

摘要

In our earlier work we have proposed and developed a methodology for the early detection of distributed denial of service (DDoS) attacks. In this paper, we examine the applicability of proactive intrusion detection on a considerably more complex set-up, with hosts associated with three clusters, connected by routers. Background TCP, UDP and ICMP traffic following interrupted Poisson processes are superimposed on the attack traffic. We have examined six types of DDoS attacks. In four of the attacks we have obtained valid MIB-based precursors with no false alarms in all experiments. In the remaining two attacks precursors were obtained, but false alarms were observed. Procedures for eliminating these false alarms are discussed.
机译:在我们的早期工作中,我们提出并开发了一种用于早期检测分布式拒绝服务(DDoS)攻击的方法。在本文中,我们研究了主动入侵检测在相当复杂的设置上的适用性,其中主机与通过路由器连接的三个集群相关联。中断的Poisson进程之后的后台TCP,UDP和ICMP流量会叠加在攻击流量上。我们已经研究了六种DDoS攻击。在四次攻击中,我们获得了有效的基于MIB的前体,在所有实验中均未出现误报。在剩下的两次袭击中,获得了先兆,但观察到了虚假警报。讨论了消除这些错误警报的过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号