• DocumentCode
    2809148
  • Title

    Analysis of the Impact of Intensive Attacks on the Self-Similarity Degree of the Network Traffic

  • Author

    Inacio, P.R.M. ; Freire, Mario M. ; Pereira, Manuela ; Monteiro, Paulo P.

  • Author_Institution
    IT-Networks & Multimedia Group, Univ. of Beira Interior, Amadora
  • fYear
    2008
  • fDate
    25-31 Aug. 2008
  • Firstpage
    107
  • Lastpage
    113
  • Abstract
    The research on how to use self-similarity for intrusion detection is not unfounded, as the scaling properties seem to partially define the very nature of aggregated traffic, and may become a potential differentiating factor in the presence of an anomaly. This paper explains how network intensive attacks can be injected into simulated traces of traffic, to then evolve to their analysis using a fast windowed version of the Variance Time (VT) estimator, optimized for the purpose of estimating the self-similarity degree in a point-by-point manner. The estimator is also applied to a trace of the well known Massachusetts Institute of Technology / Defense Advanced Research Projects Agency (MIT/DARPA) data set, leading to the conclusion that, during an attack, the insertion of a constant component may induce a significant increase of the local scope self-similarity degree, which may be used to suspect of the malicious activities and trigger further monitoring mechanisms.
  • Keywords
    computer networks; estimation theory; security of data; telecommunication security; telecommunication traffic; intrusion detection; network intensive attack; network traffic; self-similarity degree; variance time estimator; Analytical models; Computer science; Computer security; Information analysis; Information security; Intrusion detection; Multimedia systems; Operating systems; Telecommunication traffic; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Emerging Security Information, Systems and Technologies, 2008. SECURWARE '08. Second International Conference on
  • Conference_Location
    Cap Esterel
  • Print_ISBN
    978-0-7695-3329-2
  • Electronic_ISBN
    978-0-7695-3329-2
  • Type

    conf

  • DOI
    10.1109/SECURWARE.2008.28
  • Filename
    4622569