• Documents
  • Authors
  • Tables
  • Other Seers ▼
    RefSeer AckSeer CollabSeer SeerSeer
  • Log in
  • Sign up
  • MetaCart

CiteSeerX logo

Advanced Search Include Citations
Advanced Search Include Citations | Disambiguate

On scalable attack detection in the network (2007)

Cached

  • Download as a PDF

Download Links

  • [www.cs.uccs.edu]
  • [cs.uccs.edu]
  • [kailash.ucsd.edu]
  • [www.cs.ucsd.edu]
  • [kailash.ucsd.edu]
  • [www.cs.ucsd.edu]
  • [www-cse.ucsd.edu]
  • [sysnet.ucsd.edu]
  • [www.cs.ucsd.edu]
  • [www-kiv.zcu.cz]

  • Other Repositories/Bibliography

  • DBLP
  • Save to List
  • Add to Collection
  • Correct Errors
  • Monitor Changes
by Ramana Rao Kompella , Sumeet Singh , George Varghese
Citations:30 - 1 self
  • Summary
  • Active Bibliography
  • Co-citation
  • Clustered Documents
  • Version History

BibTeX

@MISC{Kompella07onscalable,
    author = {Ramana Rao Kompella and Sumeet Singh and George Varghese},
    title = {On scalable attack detection in the network},
    year = {2007}
}

Years of Citing Articles

Bookmark

citeulike Connotea Bibsonomy Del.icio.us Digg Reddit

OpenURL

 

Abstract

Current intrusion detection and prevention systems seek to detect a wide class of network intrusions (e.g., DoS attacks, worms, port scans) at network vantage points. Unfortunately, even today, many IDS systems we know of keep per-connection or per-flow state to detect malicious TCP flows. Thus, it is hardly surprising that these IDS systems have not scaled to multi-gigabit speeds. By contrast, both router lookups and fair queuing have scaled to high speeds using aggregation via prefix lookups or DiffServ. Thus, in this paper, we initiate research into the question as to whether one can detect attacks without keeping per-flow state. We will show that such aggregation, while making fast implementations possible, immediately causes two problems. First, aggregation can cause behavioral aliasing where, for example, good behaviors can aggregate to look like bad behaviors. Second, aggregated schemes are susceptible to spoofing by which the intruder sends attacks that have appropriate aggregate behavior. We examine a wide variety of DoS and scanning attacks and show that several categories (bandwidth based, claim-and-hold, port-scanning) can be scalably detected. In addition to existing approaches for scalable attack detection, we propose a novel data structure called partial completion filters (PCFs) that can detect claim-and-hold attacks scalably in the network. We analyze PCFs both analytically and using experiments on real network traces to demonstrate how we can tune PCFs to achieve extremely low false positive and false negative probabilities.

Citations

1185 Space/time trade-offs in hash coding with allowable errors - Bloom - 1970
590 Universal classes of hash functions - Carter, Wegman - 1979
564 Bro: A system for detecting network intruders in real-time. Computer Networks - Paxson - 1999
425 How to own the internet in your spare time - Staniford, Paxson, et al. - 2002
267 New Directions in Traffic Measurement and Accounting - Estan, Varghese - 2001
211 2001): The constancy of internet path properties - Zhang, Du, et al.
193 Fast Portscan Detection Using Sequential Hypothesis Testing - Jung, Paxon, et al. - 2004
185 A signal analysis of network traffic anomalies - Barford, Kline, et al. - 2002
140 Practical Automated Detection of Stealthy Portscans - Staniford, Hoagland, et al. - 2002
135 A Framework for Classifying Denial of Service Attacks - Hussain, Heidemann, et al. - 2003
130 Inferring Internet Denial of Service activity - Moore, Voelker, et al. - 2001
128 An analysis of using reflectors for Distributed Denial of Service attacks - Paxson - 2001
123 A network security monitor - HEBERLEIN, DIAS, et al. - 1990
122 A taxonomy of computer worms - Weaver, Paxson, et al. - 2003
114 Siff: A stateless internet flow filter to mitigateddosfloodingattacks - Yaar, Perrig, et al. - 2004
107 Hop-Count Filtering: An Effective Defense Against Spoofed DDoS Traffic - Jin, Wang, et al. - 2003
106 Detecting syn flooding attacks - Wang, Zhang, et al. - 2002
95 Sketch-based change detection: Methods, evaluation, and applications - Krishnamurthy, Sen, et al.
95 MULTOPS: a data-structure for bandwidth attack detection - Gil, Poleto - 2001
56 Containment of scanning worms in enterprise networks - Staniford
44 Resisting syn flood dos attacks with a syn cache - Lemon - 2002
42 An Introduction to - Larsen, Marx - 1986
37 Quicksand: Quick summary and analysis of network data - Gilbert, Guha, et al. - 2001
30 Estimating rarity and similarity over data stream windows - Datar, Muthukrishnan
29 A probabilistic approach to detecting network scans - Leckie, Kotagiri
23 Surveillance detection in high bandwidth environments - Robertson, Siegel, et al.
16 On the difficulty of scalably detecting network attacks - Levchenko, Paturi, et al.
15 Syn-dog: Sniffing syn flooding sources - Wang, Zhang, et al. - 2002
7 Analysis of a denial of service attack - Schuba, Krsul, et al. - 1997
5 A Path Identification mechanism to defend against DDoS attacks - Pi - 2003
4 Another new thought on dealing with SYN flooding - Shenk - 1996
2 The Naptha DoS vulnerabilities - Keyes
1 A tool for automatic traffic analysis - “Autofocus
1 Network security platforms will transform security markets,” 2002 [Online]. Available: http://www.techrepublic.com/article.jhtml?id=r00220021223jdt01. htm&src=bc Ramana Rao Kompella (S’03) He received the B.Tech. degree from the Indian Institute of Techno - Pescatore, Easley, et al. - 1999
The National Science Foundation
  • About CiteSeerX
  • Submit Documents
  • Privacy Policy
  • Help
  • Data
  • Source
  • Contact Us

Developed at and hosted by The College of Information Sciences and Technology

© 2007-2010 The Pennsylvania State University