Behavioral authentication of server flows

Behavioral authentication of server flows
复制标题

服务器流的行为认证

DOI:
10.1109/csac.2003.1254309
复制
发表时间:
2003
期刊:
19th Annual Computer Security Applications Conference, 2003. Proceedings.
影响因子:
--
通讯作者:
C. Rosenberg
C. Rosenberg
中科院分区:
--
文献类型:
--
作者:
James P. Early;C. Brodley;C. Rosenberg

文献摘要

被引文献

相似文献

了解流入和流出系统或网络的信息的性质对于确定是否遵守使用策略至关重要。确定流量类型的传统方法依赖于数据包标头中携带的端口标签。但是,如果代理服务器重新映射端口号或主机服务(这些服务已被破坏充当后门或隐蔽通道),则此方法可能会失败。我们提出了一种基于训练阶段学习的决策树对服务器流量进行分类的方法。这些树是根据我们设计用于捕获流行为的一组功能描述的流量构建的。由于我们对流量类型的分类与端口标签无关,因此它可以在存在恶意活动的情况下提供更准确的分类。实证评估表明,聚合协议行为和特定于主机的协议行为模型都获得了 82-100% 的分类准确率。
Understanding the nature of the information flowing into and out of a system or network is fundamental to determining if there is adherence to a usage policy. Traditional methods of determining traffic type rely on the port label carried in the packet header. This method can fail, however, in the presence of proxy servers that remap port numbers or host services that have been compromised to act as backdoors or covert channels. We present an approach to classify server traffic based on decision trees learned during a training phase. The trees are constructed from traffic described using a set of features we designed to capture stream behavior. Because our classification of the traffic type is independent of port label, it provides a more accurate classification in the presence of malicious activity. An empirical evaluation illustrates that models of both aggregate protocol behavior and host-specific protocol behavior obtain classification accuracies ranging from 82-100%.