Scalable Long-term Network Forensics for Epidemic Attacks

被引:0
作者
Chen, Li Ming [1 ]
Chen, Meng Chang [1 ]
Sun, Yeali S. [2 ]
Hsiao, Shun-Wen [2 ]
Sekar, Vyas [3 ]
Zhang, Hui [3 ]
机构
[1] Inst Informat Sci Acad Sinica, Taipei, Taiwan
[2] Natl Taiwan Univ, Dept Informat & Management, Taipei, Taiwan
[3] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
来源
2009 INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE SECURITY | 2009年
关键词
Network Forensics; Epidemic Attack; Data Reduction;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network forensics supports capabilities such as attacker identification and attack reconstruction, which complement traditional intrusion detection and perimeter defense techniques in building a robust security mechanism. Attacker identification pinpoints attack origin to deter future attackers and attack reconstruction can reveal attack causality and network vulnerabilities. In this paper, we study the problem of investigating the origin of stealthy epidemic attacks which may have long lifespan. We propose a network forensics mechanism which is scalable in time and space while maintaining high accuracy in attack origin identification. We propose a data reduction method to filter out irrelevant data and only retain evidence relevant to potential attacks for postmortem investigation. Using real trace-driven experiments, we evaluate the performance of the proposed mechanism and show that we can achieve low false positive and false negative rates in data reduction and support high scalability and accuracy in long-term network forensics.
引用
收藏
页码:71 / +
页数:2
相关论文
共 15 条
  • [1] [Anonymous], P ACM SIGCOMM AUG
  • [2] BAILEY M, 2005, P USENIX ACM INT MEA
  • [3] SPACE/TIME TRADE/OFFS IN HASH CODING WITH ALLOWABLE ERRORS
    BLOOM, BH
    [J]. COMMUNICATIONS OF THE ACM, 1970, 13 (07) : 422 - &
  • [4] Bayesian network classifiers
    Friedman, N
    Geiger, D
    Goldszmidt, M
    [J]. MACHINE LEARNING, 1997, 29 (2-3) : 131 - 163
  • [5] KUMAR A, 2005, P USENIX ACM INT MEA
  • [6] MAI J, 2006, P USENIX ACM INT MEA
  • [7] MAIER G, 2008, P ACM SIGCOMM AUG
  • [8] McDaniel P, 2006, P NETW DISTR SYST SE
  • [9] MCHUGH J, 2003, P WORKSH NEW SEC PAR
  • [10] RAJAB MA, 2005, P WORKSH RAP MALC NO