首页> 外文期刊>International journal of computer science and network security >Matching TCP/IP Packets to Detect Stepping-Stone Intrusion
【24h】

Matching TCP/IP Packets to Detect Stepping-Stone Intrusion

机译:匹配TCP / IP数据包以检测步进石入侵

获取原文
       

摘要

We propose a “Step-Function” method to detect network attackers from using a long connection chain to hide their identities when they launch attacks. The objective of the method is to estimate the length of a connection chain based on the changes in packet round trip times. The key point to compute the round trip time of a connection chain is to match a Send and its corresponding Echo packet. We propose a conservative and a greedy matching algorithm to match TCP/IP packets in real-time. The first algorithm matches fewer packets but the quality of the matching is high. The second one matches more packets with some uncertainty on the correctness. The two algorithms give us almost identical results in determining the length of a long connection chain.
机译:我们提出一种“分步功能”方法,以检测网络攻击者在发起攻击时是否使用长连接链隐藏其身份。该方法的目的是基于分组往返时间的变化来估计连接链的长度。计算连接链往返时间的关键是匹配发送及其对应的回送数据包。我们提出了一种保守和贪婪的匹配算法来实时匹配TCP / IP数据包。第一种算法匹配较少的分组,但是匹配的质量很高。第二个匹配更多的数据包,但正确性尚不确定。在确定长连接链的长度时,这两种算法给我们几乎相同的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号