【24h】

Packet tagging system for enhanced traffic profiling

机译:用于增强流量分析的数据包标记系统

获取原文

摘要

This paper describes the design and implementation of a system for managing the tagging of traffic, in order to create detailed personal and applicational profiles. The ultimate goal of this separation is to facilitate the task of traffic auditing tools, namely in their struggle against botnets. The architecture was designed for domestic or enterprise facilities and uses the 802. IX authentication architecture as the base support infrastructure for dealing with unequivocal traffic binding to specific entities (persons or servers). Simultaneously, such binding uses virtual identities and encryption for preserving the privacy and protection of traffic originators from network eavesdroppers other than authorized traffic auditors. The traffic from each known originator is profiled with some detail, namely it includes a role tag and an application tag. Role tags are defined by originators and only partially follow a standard policy. On the contrary, application tags should follow a standard policy in order to reason about abnormal scenarios raised when correlating traffic from several instances of the same application. A first prototype was developed for Linux, using iptables and FreeRADIUS and conveying packet tagging information on a new IP option field.
机译:本文介绍了用于管理流量标记的系统的设计和实现,以便创建详细的个人和应用程序配置文件。这种分离的最终目标是促进交通审计工具的任务,即他们对抗僵尸网络的斗争。该架构是为国内或企业设施设计的,并使用802.IX身份验证架构作为基础支持基础架构,用于处理与特定实体(人员或服务器)的含义绑定绑定。同时,这种绑定使用虚拟身份和加密来保护来自除授权流量审核员以外的网络窃听器的隐私和保护。来自每个已知发起者的流量以一些细节分析,即它包括角色标记和应用程序标记。角色标签由发起人定义,仅部分遵循标准策略。相反,应用程序标签应遵循标准策略,以便在关联来自同一应用程序的多个实例的流量时提出的异常方案。使用IPTables和Freeradius为Linux开发了一个第一个原型,并在新的IP选项字段上传送数据包标记信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号