首页> 外文期刊>Journal of High Speed Networks >Entropy-based analyzing anomaly WEB traffic
【24h】

Entropy-based analyzing anomaly WEB traffic

机译:基于熵的分析异常Web流量

获取原文
获取原文并翻译 | 示例
       

摘要

The application nature of HTTP protocol allows the creation of a covert timing channel based on different features of this protocol (or different levels) that has not been addressed in previous research. In this article, the entropy-based detection method was designed and implemented. The attacker can adjust the amount of channel entropy by controlling measures such as changing the channel's level or creating noise on the channel to protect from the analyzer's detection. As a result, the entropy threshold is not always constant for detection. By comparing the entropy from different levels of the channel and the analyzer, we concluded that the analyzer must investigate traffic at all possible levels. We also illustrated that by making noise on a covert channel, its capacity would decrease, but as entropy increases, it would be harder to detect it.
机译:HTTP协议的应用性质允许基于本协议(或不同级别)的不同特征创建封面定时信道,该协议在以前的研究中尚未解决。 在本文中,设计并实施了基于熵的检测方法。 攻击者可以通过控制诸如更改频道的级别或在通道上产生噪声来保护频道以保护从分析器的检测来保护通道熵量。 结果,熵阈值并不总是恒定的检测。 通过比较来自频道和分析仪的不同级别的熵,我们得出结论,分析仪必须在所有可能的水平上调查流量。 我们还说明,通过在封面通道上发出噪音,其容量会降低,但随着熵的增加,检测它更难。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号