상세 보기
A design of IPTSF (IP traceback system based on forensics) against network attacks using both BLH (black list based on a hash function) and TFAP (traffic flow analysis based on a priority)
- Jung, Ina;
- Jeong, Eunhee;
- Lee, Byungkwan
SCOPUS
0초록
This paper proposes a design of IPTSF (IP Traceback System based on Forensics) against network attacks using both BLH (Black List based on a Hash Function) and TFAP (Traffic Flow Analysis based on a Priority). The IPTSF detects attack traffics by using BLH and, diverts them to a sinkhole, not to a destination. The IPTSF marks group ID and router ID in the packets passing through routers and collects the mirroring traffic on the packets. The PFAM analyzes the attack traffic and the mirroring traffic collected by the IPTSF according to a priority and extracts attacks from them. In addition, the IPTSF reflects the result into BLH so that new attacks can be detected, and so that they can be traced back with the marked information. Therefore, using both BLH and TFAP makes an attack detection ratio even more improved than using just BLH. The statistics data by BLH and TFAP are stored in DB and are used as an evidence in a cyber investigation.
키워드
- 제목
- A design of IPTSF (IP traceback system based on forensics) against network attacks using both BLH (black list based on a hash function) and TFAP (traffic flow analysis based on a priority)
- 저자
- Jung, Ina; Jeong, Eunhee; Lee, Byungkwan
- 발행일
- 2013
- 유형
- Article
- 저널명
- Information
- 권
- 16
- 호
- 6 A
- 페이지
- 3443 ~ 3450