首页> 外文期刊>Wireless communications & mobile computing >An Efficient Security System for Mobile Data Monitoring
【24h】

An Efficient Security System for Mobile Data Monitoring

机译:用于移动数据监控的高效安全系统

获取原文
           

摘要

During the last decade, rapid development of mobile devices and applications has produced a large number of mobile data which hide numerous cyber-attacks. To monitor the mobile data and detect the attacks, NIDS/NIPS plays important role for ISP and enterprise, but now it still faces two challenges, high performance for super large patterns and detection of the latest attacks. High performance is dominated by Deep Packet Inspection (DPI) mechanism, which is the core of security devices. A new TTL attack is just put forward to escape detecting, such that the adversary inserts packet with short TTL to escape from NIDS/NIPS. To address the above-mentioned problems, in this paper, we design a security system to handle the two aspects. For efficient DPI, a new two-step partition of pattern set is demonstrated and discussed, which includes first set-partition and second set-partition. For resisting TTL attacks, we set reasonable TTL threshold and patch TCP protocol stack to detect the attack. Compared with recent produced algorithm, our experiments show better performance and the throughput increased 27% when the number of patterns is . Moreover, the success rate of detection is 100%, and while attack intensity increased, the throughput decreased.
机译:在过去的十年中,移动设备和应用程序的快速发展产生了大量隐藏了众多网络攻击的移动数据。为了监视移动数据并检测攻击,NIDS / NIPS在ISP和企业中扮演着重要角色,但是现在它仍然面临两个挑战,即超大型模式的高性能和最新攻击的检测。高性能由深度包检查(DPI)机制(安全设备的核心)主导。刚刚提出了一种新的TTL攻击以进行逃避检测,以便对手插入具有短TTL的数据包以逃离NIDS / NIPS。为了解决上述问题,在本文中,我们设计了一个安全系统来处理这两个方面。为了获得有效的DPI,演示并讨论了模式集的新两步分区,其中包括第一组分区和第二组分区。为了抵抗TTL攻击,我们设置了合理的TTL阈值并修补TCP协议栈以检测攻击。与最新产生的算法相比,我们的实验显示出更好的性能,当模式数量为时,吞吐量提高了27%。此外,检测成功率是100%,并且在增加攻击强度的同时,吞吐量降低了。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号