首页> 外文期刊>Security and communication networks >Detecting stepping-stone intrusion using association rule mining
【24h】

Detecting stepping-stone intrusion using association rule mining

机译:使用关联规则挖掘检测踏脚石入侵

获取原文
获取原文并翻译 | 示例
           

摘要

Hackers generally do not use their own computers to launch attacks on the Internet to avoid exposing their actual locations. The trick involves an intruder connecting to a victim indirectly through a sequence of hosts called stepping-stone, which makes network managers difficult to detect the intrusion, often results in serious injuries. In this study, a detection method of stepping-stone based on the association rule mining of network traffic records is proposed. The association rules establish a model for detecting stepping-stones in accordance with collecting the connecting records in the governed network. Test records are gathered from the source and destination addresses of Internet protocol in a fixed time interval, which are then analyzed with the association rules algorithm to filter out the transmission characteristics of stepping-stone attacks. In the experimental results, empirical evaluation under 5 min of test records shows that the accuracy rate, the precision rate, and the recall rate are 83.81%, 84.26%, and 83.16%, respectively. When the test record gathering time is extended to 20 min, with the same detecting method, the three evaluations achieve 99.9%. The proposed detection method may be helpful to network management for detecting suspected stepping-stone attacks. Copyright © 2013 John Wiley & Sons, Ltd.
机译:黑客通常不使用自己的计算机在Internet上发起攻击,以避免暴露其实际位置。诀窍是入侵者通过一系列称为“踏脚石”的主机间接连接到受害者,这使得网络管理员难以检测到入侵,并经常造成严重伤害。提出了一种基于网络流量记录关联规则挖掘的踏脚石检测方法。关联规则建立了一个模型,用于根据在受控网络中收集连接记录来检测踏脚石。在固定的时间间隔内从Internet协议的源地址和目标地址收集测试记录,然后使用关联规则算法对其进行分析,以过滤出踏脚石攻击的传输特征。在实验结果中,对5分钟测试记录的实证评估表明,准确率,准确率和召回率分别为83.81%,84.26%和83.16%。当测试记录收集时间延长到20分钟时,使用相同的检测方法,这三个评估的结果达到99.9%。所提出的检测方法可能有助于网络管理检测可疑的踏脚石攻击。版权所有©2013 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号