Detecting Low-Profile Probes and Novel Denial-of-Service Attacks

Detecting Low-Profile Probes and Novel Denial-of-Service Attacks
复制标题

检测低调探针和新型拒绝服务攻击

DOI:
--
复制
发表时间:
2001
期刊:
影响因子:
--
通讯作者:
R. Lippmann
R. Lippmann
中科院分区:
--
文献类型:
--
作者:
Rajlaxmi Basu;R. Cunningham;S. Webster;R. Lippmann

文献摘要

被引文献

相似文献

攻击者使用探测攻击来发现每个主机上可用的主机地址和服务。一旦知道这些信息,攻击者就可以对网络、主机或主机提供的服务发起拒绝服务攻击。这些攻击阻止访问网络的受攻击部分。直到最近,只有简单的,容易被击败的机制用于检测探测攻击。攻击者通过创建隐蔽的低姿态攻击来击败这些机制,这些攻击只包括在很长一段时间内发送的几个精心制作的数据包。此外,大多数机制不允许入侵分析人员权衡检测率和误报率。我们提出了一种方法来检测隐形攻击,实现实时检测的置信度的体系结构,和评估系统的结果。由于系统输出的是置信度值,分析师可以用误报率来衡量检测率。
Attackers use probing attacks to discover host addresses and services available on each host. Once this information is known, an attacker can then issue a denial-ofservice attack against the network, a host, or a service provided by a host. These attacks prevent access to the attacked part of the network. Until recently, only simple, easily defeated mechanisms were used for detecting probe attacks. Attackers defeat these mechanisms by creating stealthy low-profile attacks that include only a few, carefully crafted packets sent over an extended period of time. Furthermore, most mechanisms do not allow intrusion analysts to trade off detection rates for false alarm rates. We present an approach to detect stealthy attacks, an architecture for achieving real-time detections with a confidence measure, and the results of evaluating the system. Since the system outputs confidence values, an analyst can trade false alarm rate against detection rate.