DocumentCode :
2905243
Title :
Passive NATted Hosts Detect Algorithm Based on Directed Acyclic Graph Support Vector Machine
Author :
Li Rui ; Zhu Hongliang ; Xin Yang ; Luo Shoushan ; Yang, Xin ; Wang Cong
Author_Institution :
State Key Lab. of Networking & Switching Lechnology, Beijing Univ. of Posts & Telecommun., Beijing, China
Volume :
2
fYear :
2009
fDate :
18-20 Nov. 2009
Firstpage :
474
Lastpage :
477
Abstract :
Unauthorized network address translation (NAT) devices may be a significant security problem. They provide unrestricted access to any number of hosts connecting to them. Some attackers may use computers hidden behind NAT devices to conduct malicious activities such as denial of service. An algorithm is proposed in this work to detect hosts hidden behind NAT. Different from previous researches, the algorithm does not depend on any special field in any packet header. It is based on analyzing traffic features with directed acyclic graph support vector machine (DAGSVM). Firstly, traffic models of hosts are selected from training samples with DAGSVM. Then the models and classifier are used for predicting host number of unknown traces. What revealed by the experiment includes that the proposed algorithm is effective, even when there are more hosts in the test set than it is in the training set, and the accuracy will fall when there are more unknown hosts in the test traces.
Keywords :
algorithm theory; security of data; support vector machines; acyclic graph support vector machine; analyzing traffic features; conduct malicious activities; directed acyclic graph; hosts test traces; passive NATted hosts detect algorithm; predicting host number; significant security problem; support vector machine; unauthorized network address translation; unrestricted access; Computer crime; Information security; Joining processes; Laboratories; Network address translation; Operating systems; Support vector machines; TCPIP; Testing; Traffic control; directed acyclic graph; host detect; network address translation; network security; support vector machine;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Multimedia Information Networking and Security, 2009. MINES '09. International Conference on
Conference_Location :
Hubei
Print_ISBN :
978-0-7695-3843-3
Electronic_ISBN :
978-1-4244-5068-8
Type :
conf
DOI :
10.1109/MINES.2009.88
Filename :
5368737
Link To Document :
بازگشت