Enhancing performance of cardinality analysis by packet filtering

Enhancing performance of cardinality analysis by packet filtering
复制标题

DOI:
10.1109/icoin.2016.7427068
复制
发表时间:
2016-01
期刊:
2016 International Conference on Information Networking (ICOIN)
影响因子:
--
通讯作者:
S. Mori;Akira Sato;K. Yoshida
S. Mori;Akira Sato;K. Yoshida
中科院分区:
其他
文献类型:
--
作者:
S. Mori;Akira Sato;K. Yoshida

文献摘要

相似文献

网络流数据中的基数为网络管理员提供了有关网络上可疑通信的有用信息。这样的通信往往呈现异常数量的源和/或目的地网络地址。我们的研究小组报告说,在TCP/IP数据包报头中的基数可以用来检测恶意软件的传播和P2P软件的使用在小型网络。然而,对于20 Gbps以上的高速网络线路,基数分析器的处理速度不够。在本文中,我们提出了一种技术来卸载分析器的数据包过滤的基础上的TCP标志。我们还报告了所提出的技术的性能和局限性。
Cardinality in network flow data gives useful information for network administrators about suspicious communication on their network. Such communication tends to present abnormal number of source and/or destination network address. Our research group reported that cardinality presented in TCP/IP packet header can be used to detect malware propagation and P2P software usage in small size network. However the processing speed of the cardinality analyzer is not enough to analyze high speed network line over 20Gbps. In this paper, we propose a technique to offload the analyzer by packet filtering based on the TCP flags. We also report the performance and the limitation of the proposed technique.