首页> 外文学位 >A framework for collection and correlation of network forensic evidence for quality of service degradation.
【24h】

A framework for collection and correlation of network forensic evidence for quality of service degradation.

机译:用于收集和关联网络法医证据以降低服务质量的框架。

获取原文
获取原文并翻译 | 示例

摘要

The current shift from the static access based service model to the dynamic application based service model introduced major challenges for effective forensics of any quality degradation of the provided service. In addition, about 55% of the Tier 1 and Tier 2 providers are planning to offer managed security services to guarantee an attack free IP service. Meanwhile, the ability to retain the network traffic for extended period for further forensic investigation introduces another challenge. This thesis proposes a novel framework of modeling the network traffic in order to select meaningful metrics to be used in tracking the network behavior changes. Based on the deftly selected metrics, an adaptive exponentially weighted moving average (EWMA) with a moving centerline control chart is utilized to monitor the changes of the network behavior. Signaling the network behavior changes in association with the service objective based network behavioral model should provide the required information when the forensic analysis of the service quality degradation is needed with minimal storage requirements. As it will be only required to retain the selected metrics for the individualized abnormal periods. The proposed methodology is demonstrated using simulated and real traces of network behavioral metrics. This thesis illustrates the effectiveness of the forensic analysis model for the selection of relevant behavioral metrics. As well, it shows how the adaptive EWMA can be used for tracking the changes in the network behavior from normal to abnormal and vice versa and therefore bounding the storage requirement of the forensic evidence.
机译:当前从基于静态访问的服务模型向基于动态应用程序的服务模型的转变为有效地对所提供服务的任何质量下降进行取证提供了主要挑战。另外,大约55%的1级和2级提供商计划提供托管安全服务,以保证无攻击的IP服务。同时,将网络流量保留更长的时间以进行进一步的司法调查的能力带来了另一个挑战。本文提出了一种新颖的网络流量建模框架,以便选择有意义的指标来跟踪网络行为的变化。基于精挑细选的指标,具有移动中心线控制图的自适应指数加权移动平均值(EWMA)可用于监视网络行为的变化。当需要以最小的存储需求对服务质量下降进行取证分析时,用信号通知与基于服务目标的网络行为模型相关联的网络行为更改应提供所需的信息。因为仅需要为各个异常时期保留所选指标。使用网络行为指标的模拟和真实痕迹演示了所提出的方法。本文说明了取证分析模型在选择相关行为指标时的有效性。同样,它还显示了如何将自适应EWMA用于跟踪网络行为从正常到异常(反之亦然)的变化,从而限制了法医证据的存储需求。

著录项

  • 作者

    Battisha, Mohamed M.;

  • 作者单位

    University of Louisville.;

  • 授予单位 University of Louisville.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2008
  • 页码 130 p.
  • 总页数 130
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号