...
首页> 外文期刊>Journal of Universal Computer Science >Mobile Agents for Detecting Network Attacks Using Timing Covert Channels
【24h】

Mobile Agents for Detecting Network Attacks Using Timing Covert Channels

机译:使用定时隐蔽通道检测网络攻击的移动代理

获取原文
           

摘要

This article addresses the problem of network attacks using steganographic techniques based on the manipulation of time relationships between IP packets. In the study, an efficient method to detect such attacks is presented. The proposed algorithm is based on the Change Observation Theory, and employs two types of agents: base and flying ones. The agents observe the time parameters of the network traffic, using proposed meta-histograms and trained machine learning algorithms, in the node where they were installed. The results of experiments using various machine learning algorithm are presented and discussed. The study showed that the Random Forest and MLP classifiers achieved the best detection results, yielding an area under the ROC curve (AUC) above 0.85 for the evaluation data. We showed a proof-of-concept for an attack detection method that combined the classification algorithm, the proposed anomaly metrics and the mobile agents. We claim that due to a unique feature of self-regulation, realized by destroying unnecessary agents, the proposed method can establish a new type of multi-agent intrusion detection system that can be applied to a wider group of IT systems.
机译:本文解决了基于IP数据包之间时间关系操纵的使用隐写技术的网络攻击问题。在这项研究中,提出了一种检测此类攻击的有效方法。所提出的算法基于变化观察理论,并采用两种类型的代理:基础代理和飞行代理。代理使用建议的元直方图和训练有素的机器学习算法,在安装它们的节点中观察网络流量的时间参数。提出并讨论了使用各种机器学习算法的实验结果。研究表明,随机森林和MLP分类器获得了最佳检测结果,评估数据的ROC曲线下面积(AUC)大于0.85。我们展示了一种结合了分类算法,拟议的异常度量和移动代理的攻击检测方法的概念证明。我们声称,由于具有通过破坏不必要的代理程序实现的自我调节的独特功能,因此所提出的方法可以建立一种新型的多代理程序入侵检测系统,该系统可以应用于更广泛的IT系统中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号