RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    Internet Attack Visualization on High-Speed Networks

    한글로보기

    https://www.riss.kr/link?id=T10709763

    • 저자
    • 발행사항

      서울 : 고려대학교 대학원, 2006

    • 학위논문사항

      학위논문(석사) -- 고려대학교 대학원 , 컴퓨터학과 전산학전공 , 2006.8

    • 발행연도

      2006

    • 작성언어

      영어

    • 발행국(도시)

      서울

    • 형태사항

      iv, 37 p. : 삽도 ; 26 cm.

    • 일반주기명

      단면인쇄임
      지도교수: 김효곤
      참고문헌 : p. 36-37

    • 소장기관
      • 고려대학교 과학도서관 소장기관정보
      • 고려대학교 도서관 소장기관정보
      • 고려대학교 세종학술정보원 소장기관정보
    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    인터넷상의 수많은 트래픽 정보 중에서 악성 트래픽 정보를 빠르게 감지하는 것은 그 정보의 방대함 때문에 쉽지 않다. 공격시각화(Attack Visualization) 기법은 이런 수많은 정보 중에서 악성 트래픽 정보를 좀 더 쉽게 인지하게 함으로써 새로운 공격에 대해서 빠른 대응과 피해 최소화를 하는데 활용할 수 있다. 본 연구에서는 평행좌표계(Parallel Coordinates)를 이용해 공격시각화를 하여, 분산 서비스 거부 공격, 웜, 스캐닝 공격 등 인터넷상에 알려진, 혹은 알려지지 않은 새로운 공격들에 대해 빠른 대응을 하기위한 기술 연구를 하였으며, 각 공격들의 특정 시각화 패턴을 감지하고 이를 알려주는 이상탐지(anomaly detection) 시각화 시스템 PCAV를 구현하였다. PCAV 시스템을 통해 네트워크 관리자는 실시간으로 트래픽 정보와 공격들의 시각화 정보를 원격에서도 모니터링하고 이를 통해 즉시 대응하는 것이 가능하다. 또한, 이전에 발생한 공격들의 시각화 정보를 확인하고 이를 분석하는 것과, 알려지지 않은 공격이 발생했을지라도 그 공격의 시각적 패턴이 나타났을 때 즉각 공격 서명(signature)으로 활용 하는 것이 가능하다.
    번역하기

    인터넷상의 수많은 트래픽 정보 중에서 악성 트래픽 정보를 빠르게 감지하는 것은 그 정보의 방대함 때문에 쉽지 않다. 공격시각화(Attack Visualization) 기법은 이런 수많은 정보 중에서 악성 트...

    인터넷상의 수많은 트래픽 정보 중에서 악성 트래픽 정보를 빠르게 감지하는 것은 그 정보의 방대함 때문에 쉽지 않다. 공격시각화(Attack Visualization) 기법은 이런 수많은 정보 중에서 악성 트래픽 정보를 좀 더 쉽게 인지하게 함으로써 새로운 공격에 대해서 빠른 대응과 피해 최소화를 하는데 활용할 수 있다. 본 연구에서는 평행좌표계(Parallel Coordinates)를 이용해 공격시각화를 하여, 분산 서비스 거부 공격, 웜, 스캐닝 공격 등 인터넷상에 알려진, 혹은 알려지지 않은 새로운 공격들에 대해 빠른 대응을 하기위한 기술 연구를 하였으며, 각 공격들의 특정 시각화 패턴을 감지하고 이를 알려주는 이상탐지(anomaly detection) 시각화 시스템 PCAV를 구현하였다. PCAV 시스템을 통해 네트워크 관리자는 실시간으로 트래픽 정보와 공격들의 시각화 정보를 원격에서도 모니터링하고 이를 통해 즉시 대응하는 것이 가능하다. 또한, 이전에 발생한 공격들의 시각화 정보를 확인하고 이를 분석하는 것과, 알려지지 않은 공격이 발생했을지라도 그 공격의 시각적 패턴이 나타났을 때 즉각 공격 서명(signature)으로 활용 하는 것이 가능하다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    This research presents PCAV (Parallel Coordinates Attack Visualizer), a real-time visualization system for detecting large-scale Internet attacks including Internet worms, DDoS attacks and network scanning activities. PCAV displays network traffic on the plane of parallel coordinates using the source IP address, destination IP address, destination port and the average packet length in a flow. These four values are used to draw each flow as a connected line on the plane and surprisingly a group of lines form a particular shape in case of attack. Thus, a simple but novel way of displaying traffic reveals ongoing attacks. From the fact that numerous types of attacks form a specific pattern of graphs, we have developed nine signatures and their detection mechanism using an efficient hashing algorithm. Using the graphical signatures, PCAV can quickly detect new attacks and enables network administrators to instantly recognize and respond to the attacks. Another strength of PCAV comes from handling flows instead of packets. Per-flow visualization greatly reduces the processing time and further provides compatibility with legacy routers which export flow information such as NetFlow in Cisco routers. We have demonstrated the effectiveness of PCAV using real traffic evaluation and the result of evaluation shows that PCAV greatly detects several attacks even if types of attacks are different or not, under gigabit speed network with high accuracy
    번역하기

    This research presents PCAV (Parallel Coordinates Attack Visualizer), a real-time visualization system for detecting large-scale Internet attacks including Internet worms, DDoS attacks and network scanning activities. PCAV displays network traffic on ...

    This research presents PCAV (Parallel Coordinates Attack Visualizer), a real-time visualization system for detecting large-scale Internet attacks including Internet worms, DDoS attacks and network scanning activities. PCAV displays network traffic on the plane of parallel coordinates using the source IP address, destination IP address, destination port and the average packet length in a flow. These four values are used to draw each flow as a connected line on the plane and surprisingly a group of lines form a particular shape in case of attack. Thus, a simple but novel way of displaying traffic reveals ongoing attacks. From the fact that numerous types of attacks form a specific pattern of graphs, we have developed nine signatures and their detection mechanism using an efficient hashing algorithm. Using the graphical signatures, PCAV can quickly detect new attacks and enables network administrators to instantly recognize and respond to the attacks. Another strength of PCAV comes from handling flows instead of packets. Per-flow visualization greatly reduces the processing time and further provides compatibility with legacy routers which export flow information such as NetFlow in Cisco routers. We have demonstrated the effectiveness of PCAV using real traffic evaluation and the result of evaluation shows that PCAV greatly detects several attacks even if types of attacks are different or not, under gigabit speed network with high accuracy

    더보기

    목차 (Table of Contents)

    • Contents
    • 1. Abstract
    • 2. Introduction
    • 3. Attack Visualization
    • 3.1 Benefits of Attack Visualization
    • Contents
    • 1. Abstract
    • 2. Introduction
    • 3. Attack Visualization
    • 3.1 Benefits of Attack Visualization
    • 3.2 Attack Characteristics
    • 3.3 Four fields as Attack Parameters
    • 3.4 Per-flow Visualization
    • 3.5 Parallel Coordinates
    • 4. Parallel Coordinates Attack Visualization
    • 4.1 Attack Signatures
    • 4.2 System Design
    • 4.3 Attack Detection Algorithm
    • 5. Evaluation
    • 5.1 Case Study
    • 5.2 Stress Test
    • 5.3 Multiple Attack Test
    • 5.4 False Alarms
    • 5.5 Reflection of attack
    • 6. Related Works
    • 7. Conclusion
    • 국문 요약
    • Reference
    • List of Figures
    • 1. Rescaled attack graphs
    • 2. System design of PCAV
    • 3. PCAVflow data generated from sensor
    • 4. Attack detection algorithm in the analyzer
    • 5. Reported attack graphs
    • 6. Processing ratio of PCAV
    • 7. Detecting ratio of multiple attack test
    • 8. Interference relationship of each attack
    • 9. Approximated detecting ratio graph
    • 10. False alarm test
    • 11. False alarms of worm
    • 12. Reflections
    • List of Tables
    • 1. Properties of famous worms
    • 2. Attack signatures of nine attacks
    • 3. Comparisons of data structures
    • 4. Parameters in evaluation
    • 5. Notable reflections
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼