فری پیپر سرویس دانلود رایگان مقالات علمی

۲ مطلب با کلمه‌ی کلیدی «DDoS» ثبت شده است

[ترجمه مقاله] مدل کاهشِ مسیر یابی سیلابی( TCP SYN با جعل IP )

Abstract

DDoS attack is considered to be a major threat among security problems in today's Internet. These kinds of attack are potentially severe. They bring down business of company drastically. DDoS attack can easily exhaust the computing and communication resources of its victim within a short period of time. There are attacks exploiting some vulnerability or implementation bug in the software implementation of a service, to bring the server down. Some attacks will use all the available resources at the target machine. This paper deals on attacks that consume all the bandwidth available to the victim machine. While concentrating on the bandwidth attack the TCP SYN flood is the more prominent attack. TCP/IP protocol suite is the most widely used protocol suite for data communication. The TCP SYN flood works by exhausting the TCP connection queue of the host and thus denying legitimate connection requests. There are various methods used to detect and prevent this attack, one of which is to block the packet based on SYN flag count from the same IP address. This kind of prevention methods becomes unsuitable when the attackers use the Spoofed IP address. For the prevention of this kind of attacks, the TCP specific probing is used in the proposed scheme where the client is requested to change the windows size/ cause packet retransmission while sending the ACK in the three way hand shake. This is very useful to find the Spoofed IP Packets/TCP SYN flood and preventing them.

http://ieeexplore.ieee.org/xpl/articleDetails.jsp?arnumber=5972435

ادامه مطلب...
۰۲ شهریور ۹۴ ، ۱۷:۴۷ موافقین ۰ مخالفین ۰

[ترجمه مقاله] روش احتمالاتی پیشرفته برای پیش بینی و کشف نفوذ به شبکه

Abstract

Recently, as damage caused by Internet threats has increased significantly, one of the major challenges is to accurately predict the period and severity of threats. In this study, a novel probabilistic approach is proposed effectively to forecast and detect network intrusions. It uses a Markov chain for probabilistic modeling of abnormal events in network systems. First, to define the network states, we perform K-means clustering, and then we introduce the concept of an outlier factor. Based on the defined states, the degree of abnormality of the incoming data is stochastically measured in real-time. The performance of the proposed approach is evaluated through experiments using the well-known DARPA 2000 data set and further analyzes. The proposed approach achieves high detection performance while representing the level of attacks in stages. In particular, our approach is shown to be very robust to training data sets and the number of states in the Markov model.

http://www.sciencedirect.com/science/article/pii/S0957417412009128

ادامه مطلب...
۳۱ مرداد ۹۴ ، ۰۱:۲۴ موافقین ۰ مخالفین ۰