(A) statistical approach to network detection on backbone links대규모 기간망에서의 네트워크 공격탐지를 위한 통계적 기법에 관한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 515
  • Download : 0
Several network attacks, such as distributed denial of service (DDoS) attack, presents a very serious threat to the stability of the internet. The threat posed by network attacks on large networks, such as the internet, demands effective detection method. Therefore, a simple intrusion detection system on large-scale backbone network is needed for the sake of real-time detection, preemption and detection efficiency. In this paper, in order to discriminate attack traffic from legitimate traffic on backbone links, we suggest a relatively simple statistical measure, entropy, which can track value frequency. Because according to network attacks, there should be unusual value frequency in source IP, destination IP and destination port, we observe changes of entropy value for three selected packet attributes. In order to evaluate our detecting algorithm, we experimented with 2000 DARPA Intrusion Detection Scenario Specific Data Sets. The result shows that network attack packets show anomalies in entropy values of selected packet attributes. In other words, there is conspicuous distinction of entropy values between attack traffic and legitimate traffic. And also according to the type of the network attacks, there are significant differences of the entropy values. Therefore, we can identify what kind of attack it is as well as detecting the attack traffic using entropy value.
Advisors
Kim, Se-Hunresearcher김세헌researcher
Description
한국과학기술원 : 산업공학과,
Publisher
한국과학기술원
Issue Date
2005
Identifier
243564/325007  / 020033088
Language
eng
Description

학위논문(석사) - 한국과학기술원 : 산업공학과, 2005.2, [ ii, 45 p. ]

Keywords

Backbone Links; Statistical Approach; DDoS; Intrusion Detection; Shear testtical tail wingnspection; 전단시험; 압축시험; 대규모 기간망 층간전단시험; 통계적 기법; 분산 서비스 공격; 침입탐지

URI
http://hdl.handle.net/10203/40695
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=243564&flag=dissertation
Appears in Collection
IE-Theses_Master(석사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0