Fingerprinting Network Entities Based on Traffic Analysis in High-Speed Network Environment

Fingerprinting Network Entities Based on Traffic Analysis in High-Speed Network Environment
复制标题

高速网络环境下基于流量分析的网络实体指纹识别

DOI:
10.1155/2018/6124160
复制
发表时间:
2018-12
期刊:
Security and Communication Networks (SCN)
影响因子:
--
通讯作者:
Zhen Ling
Zhen Ling
中科院分区:
其他
文献类型:
--
作者:
Xiaodan Gu;Ming Yang;Yiting Zhang;Peilong Pan;Zhen Ling

文献摘要

参考文献

相似文献

对于入侵检测来说,检测可疑实体和潜在威胁变得越来越重要。在本文中,我们引入网络实体识别技术来检测潜在的入侵者。然而,如果标识符被隐藏或篡改,则基于MAC地址、IP地址或其他显式标识符的传统实体识别技术可以被停用。同时,现有的指纹识别技术也受到其性能有限和时延过大的限制。为了实现高速网络环境下的实体识别,分别使用PFQ内核模块和Storm进行高速数据包捕获和在线流量分析。在此基础上,提出了一种新的基于运行环境分析的设备指纹识别技术,该技术采用Logistic回归的滑动窗口机制实现在线识别,在60分钟内的识别率达到77.03%。为了实现跨设备的用户身份识别,利用多项朴素贝叶斯模型提取Web访问记录、DNS响应中的域名和HTTP用户代理信息,构成在线身份识别的用户行为指纹。当最小有效特征维度设置为9时,仅需5分钟即可达到79.51%的准确率。性能测试结果表明,所提出的方法可以支持10Gbps以上的流量捕获和在线分析,该系统架构在实践中是正确的,具有很好的实用性和可扩展性。
For intrusion detection, it is increasingly important to detect the suspicious entities and potential threats. In this paper, we introduce the identification technologies of network entities to detect the potential intruders. However, traditional entities identification technologies based on the MAC address, IP address, or other explicit identifiers can be deactivated if the identifier is hidden or tampered. Meanwhile, the existing fingerprinting technology is also restricted by its limited performance and excessive time lapse. In order to realize entities identification in high-speed network environment, PFQ kernel module and Storm are used for high-speed packet capture and online traffic analysis, respectively. On this basis, a novel device fingerprinting technology based on runtime environment analysis is proposed, which employs logistic regression to implement online identification with a sliding window mechanism, reaching a recognition accuracy of 77.03% over a 60-minute period. In order to realize cross-device user identification, Web access records, domain names in DNS responses, and HTTP User-Agent information are extracted to constitute user behavioral fingerprints for online identification with Multinomial Naive Bayes model. When the minimum effective feature dimension is set to 9, it takes only 5 minutes to reach an accuracy of 79.51%. Performance test results show that the proposed methods can support over 10Gbps traffic capture and online analysis, and the system architecture is justified in practice because of its practicability and extensibility.
DOI: 10.1007/978-3-642-30436-1_20
发表时间: 2012-06
期刊: --
影响因子: --
作者:
Christian Banse;Dominik Herrmann;H. Federrath
通讯作者: Christian Banse;Dominik Herrmann;H. Federrath
一种基于行为模式跟踪用户的新颖攻击
DOI: 10.1002/cpe.3891
发表时间: 2017
影响因子: 2
作者:
Gu Xiaodan;Yang Ming;Shi Congcong;Ling Zhen;Luo Junzhou
通讯作者: Luo Junzhou
DOI: 10.1145/2046707.2046725
发表时间: 2011-10
期刊: --
影响因子: --
作者:
Nan Zheng;Aaron Paloski;Haining Wang
通讯作者: Nan Zheng;Aaron Paloski;Haining Wang
DOI: 10.1515/popets-2015-0027
发表时间: 2016
影响因子: --
作者:
Andreas Kurtz;Hugo Gascon;Tobias Becker;Konrad Rieck;F. Freiling
通讯作者: Andreas Kurtz;Hugo Gascon;Tobias Becker;Konrad Rieck;F. Freiling
DOI: 10.1145/1287853.1287866
发表时间: 2007-09
期刊: --
影响因子: --
作者:
Jeffrey Pang;Ben Greenstein;R. Gummadi;S. Seshan;D. Wetherall
通讯作者: Jeffrey Pang;Ben Greenstein;R. Gummadi;S. Seshan;D. Wetherall