首页> 外国专利> LIGHT WEIGHT DISTRIBUTED INTRUSION DETECTION SYSTEM

LIGHT WEIGHT DISTRIBUTED INTRUSION DETECTION SYSTEM

机译:轻型分布式入侵检测系统

摘要

Network Intrusion Detection System sniffs network traffic of entire network and converts it into network traffic (i.e. network connection) records. These records contains many features (i.e. attributes) like ˜Source to destination Bytes™, ˜Destination to source Bytes™, ˜Duration of connection™, ˜Percentage of connections having error™, ˜Status of connection™. Under the presence of attack some of the network connection features indicates the error. These features are ˜% of connection to same host machine having SYN error™, ˜% of connection to same host machine having REJ error™, ˜% of connection to same service having SYN error™, etc. Proposed methodology herewith is used to detect DoS/DDoS attacks. It first looks for existence of error in the network traffic record and if error is present in it then only that record will be further analyzed for possible DoS/DDoS attack. This reduces the amount of data need to be analyzed for detection of DOS/DDoS attack.
机译:网络入侵检测系统会嗅探整个网络的网络流量,并将其转换为网络流量(即网络连接)记录。这些记录包含许多功能(即属性),例如〜“源到目标Bytes™”,“目标到源Bytes™”,“连接持续时间”,“具有错误的连接百分比”,“连接状态”。在受到攻击的情况下,某些网络连接功能会指示错误。这些功能是〜具有SYN error™的同一主机的连接的%,〜具有REJ error™的同一主机的连接的%,〜具有SYN error™的同一服务的连接的%,等等。提议的方法用于检测DoS / DDoS攻击。它首先查找网络流量记录中是否存在错误,如果其中存在错误,则仅对该记录进行进一步分析,以进行可能的DoS / DDoS攻击。这减少了检测DOS / DDoS攻击所需分析的数据量。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号