首页> 外文期刊>電子情報通信学会技術研究報告 >Euclidian- and Cosine-Distances based Detection of Distributed Host Search Attacks
【24h】

Euclidian- and Cosine-Distances based Detection of Distributed Host Search Attacks

机译:基于欧氏距离和余弦距离的分布式主机搜索攻击检测

获取原文
获取原文并翻译 | 示例
       

摘要

We statistically investigated the total PTR resource record (RR) based DNS query request packet traffic from the Internet to the top domain DNS server in a university campus network through January 1st to December 31st, 2011. The obtained results are: (1) We found twelve host search (HS) attacks in the scores for detection method using the calculated Euclidean distances between the observed IP address and the last observed IP address in the DNS query keywords by employing both threshold ranges of 1.0-2.0 (consecutive) and 150.2-210.4 (random). However, we found nineteen HS attacks in the scores using the calculated cosine distance between the DNS query IP addresses (threshold ranges of 0.75-0.83 and 0.9-1.0). (3) In the newly found HS attacks, we observed that the source IP addresses of the HS attack DNS query packets are distributed Therefore, it can be concluded that the cosine distance based detection technology can detect the source IP address-distributed host search attack.
机译:我们对截至2011年1月1日至12月31日从Internet到大学校园网络中顶级域DNS服务器的基于PTR资源记录(RR)的DNS查询请求数据包流量进行了统计调查。获得的结果是:(1)我们发现通过使用1.0-2.0(连续)和150.2-210.4的两个阈值范围,使用DNS查询关键字中观察到的IP地址和最后观察到的IP地址之间的计算出的欧几里得距离,对检测方法的分数进行十二次主机搜索(HS)攻击(随机)。但是,我们使用计算出的DNS查询IP地址之间的余弦距离(阈值范围0.75-0.83和0.9-1.0)在分数中发现了19次HS攻击。 (3)在新发现的HS攻击中,我们观察到HS攻击DNS查询数据包的源IP地址是分布式的,因此可以得出结论,基于余弦距离的检测技术可以检测到源IP地址分布的主机搜索攻击。

著录项

  • 来源
    《電子情報通信学会技術研究報告》 |2012年第485期|p.179-184|共6页
  • 作者单位

    Center for Multimedia and Information Technologies (CMIT), Kumamoto University;

    Department of Computer Science and Electrical Engineering, Faculty of Engineering, Kumamoto University;

    Human Resource Center for Innovation, Kumamoto University;

    Center for Multimedia and Information Technologies (CMIT), Kumamoto University;

    Center for Multimedia and Information Technologies (CMIT), Kumamoto University;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-18 00:28:58

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号