首页> 外文会议>Proceedings of the 5th International Conference on Data Communication Networking >Towards identification of operating systems from the internet traffic: IPFIX monitoring with fingerprinting and clustering
【24h】

Towards identification of operating systems from the internet traffic: IPFIX monitoring with fingerprinting and clustering

机译:从互联网流量中识别操作系统:具有指纹和群集功能的IPFIX监视

获取原文
获取原文并翻译 | 示例

摘要

This paper deals with identification of operating systems (OSs) from the Internet traffic. Every packet injected on the network carries a specific information in its packet header that reflects the initial settings of a host's operating system. The set of such features forms a fingerprint. The OS fingerprint usually includes an initial TTL time, a TCP initial window time, a set of specific TCP options, and other values obtained from IP and TCP headers. Identification of OSs can be useful for monitoring a traffic on a local network and also for security purposes. In our paper we focus on the passive fingerprinting using TCP SYN packets that is incorporated to a IPFIX probe. Our tool enhances standard IPFIX records by additional information about OSs. Then, it sends the records to an IPFIX collector where network statistics are stored and presented to the network administrator. If identification is not successful, a further HTTP header check is employed and the fingerprinting database in the probe is updated. Our fingerprinting technique can be extended using cluster analysis as presented in this paper. As we show the clustering adds flexibility and dynamics to the fingerprinting. We also discuss the impact of IPv6 protocol on the passive fingerprinting.
机译:本文涉及从Internet流量中识别操作系统(OS)。网络上注入的每个数据包在其数据包头中都包含一个特定的信息,该信息反映了主机操作系统的初始设置。这种特征的集合形成指纹。 OS指纹通常包括初始TTL时间,TCP初始窗口时间,一组特定的TCP选项以及从IP和TCP标头获得的其他值。操作系统的标识对于监视本地网络上的流量以及出于安全目的很有用。在我们的论文中,我们专注于使用集成到IPFIX探针中的TCP SYN数据包进行被动指纹识别。我们的工具通过有关操作系统的其他信息来增强标准IPFIX记录。然后,它将记录发送到IPFIX收集器,在该收集器中存储网络统计信息并将其提供给网络管理员。如果识别不成功,则使用进一步的HTTP标头检查,并更新探针中的指纹数据库。如本文所述,可以使用聚类分析扩展我们的指纹技术。正如我们所展示的,聚类为指纹添加了灵活性和动态性。我们还将讨论IPv6协议对被动指纹的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号