...
首页> 外文期刊>Computers & Security >Extensions to the source path isolation engine for precise and efficient log-based IP traceback
【24h】

Extensions to the source path isolation engine for precise and efficient log-based IP traceback

机译:源路径隔离引擎的扩展,可进行精确,高效的基于日志的IP追溯

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

IP traceback is used to determine the source and path traversed by a packet received from the Internet. In this work we first show that the Source Path Isolation Engine (SPIE), a classical log-based IP traceback system, can return misleading attack graphs in some particular situations, which may even make it impossible to determine the real attacker. We show that by unmasking the TTL field SPIE returns a correct attack graph that precisely identifies the route traversed by a given packet allowing the correct identification of the attacker. Nevertheless, an unmasked TTL poses new challenges in order to preserve the confidentiality of the communication among the system's components. We solve this problem presenting two distributed algorithms for searching across the network overlay formed by the packet log bases. Two other extensions to SPIE are proposed that improve the efficiency of source discovery: separate logs are kept for each router interface improving the distributed search procedure; an efficient dynamic log paging strategy is employed, which is based on the actual capacity factor instead of the fixed time interval originally employed by SPIE. The system was implemented and experimental results are presented.
机译:IP追溯用于确定从Internet接收的数据包遍历的源和路径。在这项工作中,我们首先证明源路径隔离引擎(SPIE)是一种经典的基于日志的IP回溯系统,在某些特定情况下可以返回误导性攻击图,甚至可能无法确定真正的攻击者。我们显示出,通过取消屏蔽TTL字段,SPIE返回正确的攻击图,该图准确地标识给定数据包遍历的路由,从而可以正确识别攻击者。然而,为了保护系统组件之间通信的机密性,未屏蔽的TTL提出了新的挑战。我们解决了这个问题,提出了两种分布式算法,用于搜索由数据包日志库形成的网络覆盖。提出了SPIE的另外两个扩展,可以提高源发现的效率:为每个路由器接口保留单独的日志,以改善分布式搜索过程;采用了一种有效的动态日志分页策略,该策略基于实际的容量因子,而不是SPIE最初使用的固定时间间隔。该系统已实现并给出了实验结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号