【24h】

RIHT: A Novel Hybrid IP Traceback Scheme

机译:右图:一种新型的混合IP回溯方案

获取原文
获取原文并翻译 | 示例
           

摘要

Because the Internet has been widely applied in various fields, more and more network security issues emerge and catch people's attention. However, adversaries often hide themselves by spoofing their own IP addresses and then launch attacks. For this reason, researchers have proposed a lot of traceback schemes to trace the source of these attacks. Some use only one packet in their packet logging schemes to achieve IP tracking. Others combine packet marking with packet logging and therefore create hybrid IP traceback schemes demanding less storage but requiring a longer search. In this paper, we propose a new hybrid IP traceback scheme with efficient packet logging aiming to have a fixed storage requirement for each router (under 320 KB, according to CAIDA's skitter data set) in packet logging without the need to refresh the logged tracking information and to achieve zero false positive and false negative rates in attack-path reconstruction. In addition, we use a packet's marking field to censor attack traffic on its upstream routers. Lastly, we simulate and analyze our scheme, in comparison with other related research, in the following aspects: storage requirement, computation, and accuracy.
机译:由于互联网已经在各个领域得到了广泛的应用,因此越来越多的网络安全问题引起人们的关注。但是,攻击者通常通过欺骗自己的IP地址然后发起攻击来隐藏自己。因此,研究人员提出了许多追溯方案来追踪这些攻击的来源。有些人在其数据包记录方案中仅使用一个数据包即可实现IP跟踪。其他一些将数据包标记与数据包日志记录结合在一起,因此创建了混合IP跟踪方案,该方案要求较少的存储空间但需要更长的搜索时间。在本文中,我们提出了一种具有高效数据包日志记录功能的新型混合IP追溯方案,旨在在数据包日志记录中对每个路由器有固定的存储要求(根据CAIDA的数据集,不足320 KB),而无需刷新记录的跟踪信息并在攻击路径重建中实现零误报率和误报率。此外,我们使用数据包的标记字段来检查其上游路由器上的攻击流量。最后,与其他相关研究相比,我们在以下几个方面对方案进行了仿真和分析:存储需求,计算和准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号