...
首页> 外文期刊>International Journal of Internet Technology and Secured Transactions >A comparative study of attributes for gathering admissible evidence in the investigation of distributed denial of service (DDoS) attacks
【24h】

A comparative study of attributes for gathering admissible evidence in the investigation of distributed denial of service (DDoS) attacks

机译:在调查分布式拒绝服务(DDoS)攻击中收集可采证据的属性的比较研究

获取原文
获取原文并翻译 | 示例
           

摘要

Global crises have widened the scope of criminal activities that intruders commit on computer networks. However, available litigations to charge intruders are ineffective because most electronic evidence obtained from intrusion logs are inadmissible in several courts of law. Therefore, this paper critically discusses the concept of admissible evidence in courts of law and how forensics experts can extract them from intrusion logs. This paper also discusses a model that adopts information theory to reclassify attributes of intrusions that are used to extract admissible evidence. Evaluations demonstrate that majority of the attributes of distributed denial of service attacks are less informative. The results suggest that type of service, TCP flags, TTL, length of packet, destination IP address, TCP acknowledgement and IP protocol are less informative while source addresses, destination port address and timestamp are informative attributes for forensics investigation of distributed denial of service attacks investigated in this paper.
机译:全球危机扩大了入侵者在计算机网络上从事的犯罪活动的范围。但是,可用于起诉入侵者的诉讼无效,因为从入侵日志中获得的大多数电子证据在几个法院都是不允许的。因此,本文批判性地讨论了法院可接受证据的概念,以及法医专家如何从入侵日志中提取证据。本文还讨论了一种模型,该模型采用信息论对用于提取可采证据的入侵属性进行重新分类。评估表明,分布式拒绝服务攻击的大多数属性信息较少。结果表明,服务类型,TCP标志,TTL,数据包长度,目标IP地址,TCP确认和IP协议提供的信息较少,而源地址,目标端口地址和时间戳是提供信息的属性,可用于对分布式拒绝服务攻击进行法医调查本文进行了调查。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号