DocumentCode :
2374671
Title :
An efficient sequential watermark detection model for tracing network attack flows
Author :
Wang, Xiaogang ; Luo, Junzhou ; Yang, Ming
Author_Institution :
Sch. of Comput. Sci. & Eng., Southeast Univ., Nanjing, China
fYear :
2012
fDate :
23-25 May 2012
Firstpage :
236
Lastpage :
243
Abstract :
Watermarking schemes for tracing network attack flows have been proposed to detect stepping-stone intrusion and fight against the abuse of anonymity. However, most existing network flow watermark detection techniques focus on fixed sample size of network data, thus resulting in not only unguaranteed rates of detection errors but also low efficiency of watermark detection. We herein propose an efficient sequential watermark detection (ESWD) model for tracing network attack flows. Based on the ESWD model, a statistical analysis of sequential detectors, with no assumptions or limitations concerning the distribution of the timing of packets, proves their effectiveness despite traffic timing perturbations. The experiments using a large number of synthetically-generated SSH traffic flows demonstrate that there is a significant advantage in using the ESWD model over the existing fixed sample size (FSS) detector, where the optimal sequential watermark detector (OSWD) based on the ESWD model results in almost 28% savings in the average number of packets compared to the FSS watermark detector. Furthermore, the nonparametric sequential sign watermark detector (SSWD) can also reduce the average packet number, given the required probability of detection errors.
Keywords :
Internet; statistical analysis; watermarking; ESWD; FSS watermark detector; Internet; OSWD; fixed sample size detector; network attack flows; network flow watermark detection techniques; optimal sequential watermark detector; sequential detectors; sequential watermark detection model; statistical analysis; stepping-stone intrusion; synthetically-generated SSH traffic flows; watermarking schemes; Artificial intelligence; Detectors; Frequency selective surfaces; Watermarking; interval centroid-based watermark; network attack flow; sequential probability ratio test; traceback; watermarking;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Supported Cooperative Work in Design (CSCWD), 2012 IEEE 16th International Conference on
Conference_Location :
Wuhan
Print_ISBN :
978-1-4673-1211-0
Type :
conf
DOI :
10.1109/CSCWD.2012.6221824
Filename :
6221824
Link To Document :
بازگشت