Collaborative anomaly-based detection of large-scale internet attacks

被引:14
|
作者
Gamer, Thomas [1 ]
机构
[1] KIT, Inst Telemat, D-76131 Karlsruhe, Germany
关键词
Attack detection; Collaboration; Large-scale attacks; INTRUSION;
D O I
10.1016/j.comnet.2011.08.015
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet infrastructure and Internet-based business today still suffer from various attacks like Distributed Denial-of-Service (DDoS) attacks or worm propagations. A necessary first step in order to cope with such large-scale attacks is to provide an Internet-wide detection of such ongoing attacks, i.e., a detection that is not limited to single detection systems only. Therefore, collaborative detection systems were developed in the past. They, however, often rely on close trust relationships, which only rarely are available in the Internet. This means that the scope of detection is limited to only a small part of the Internet, mostly to a single administrative domain. This paper, therefore, introduces our newly developed collaborative attack detection that facilitates collaboration beyond domain boundaries without requiring close trust relationships. In-network detection systems are explicitly considered, too. Such systems are located on routers in the core of the Internet and are characterized by limited resources available for detection. Finally, a detailed simulative levaluation of our proposed solution is presented. (C) 2011 Elsevier B.V. All rights reserved.
引用
收藏
页码:169 / 185
页数:17
相关论文
共 50 条
  • [1] Anomaly-based Identification of Large-Scale Attacks
    Gamer, Thomas
    GLOBECOM 2009 - 2009 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-8, 2009, : 6638 - 6643
  • [2] Anomaly-based intrusion detection of jamming attacks, local versus collaborative detection
    Fragkiadakis, Alexandros G.
    Siris, Vasilios A.
    Petroulakis, Nikolaos E.
    Traganitis, Apostolos P.
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2015, 15 (02): : 276 - 294
  • [3] Collaborative anomaly-based attack detection
    Gamer, Thomas
    Scharf, Michael
    Schoeller, Marcus
    SELF-ORGANIZING SYSTEMS, PROCEEDINGS, 2007, 4725 : 280 - +
  • [4] Robust and efficient detection of DDoS attacks for large-scale internet
    Lu, Kejie
    Wu, Dapeng
    Fan, Heyan
    Todorovic, Sinisa
    Nucci, Antonio
    COMPUTER NETWORKS, 2007, 51 (18) : 5036 - 5056
  • [5] An Anomaly-Based IDS for Detecting Attacks in RPL-Based Internet of Things
    Farzaneh, Behnam
    Montazeri, Mohammad Ali
    Jamali, Shahram
    2019 5TH INTERNATIONAL CONFERENCE ON WEB RESEARCH (ICWR), 2019, : 61 - 66
  • [6] Crowdsourcing based large-scale network anomaly detection
    Li, Yang
    Huang, Wenguang
    Tian, Xiaohua
    2018 10TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS AND SIGNAL PROCESSING (WCSP), 2018,
  • [7] Hierarchical Anomaly-Based Detection of Distributed DNS Attacks on Enterprise Networks
    Lyu, Minzhao
    Gharakheili, Hassan Habibi
    Russell, Craig
    Sivaraman, Vijay
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (01): : 1031 - 1048
  • [8] Anomaly-Based Detection and Classification of Attacks in Cyber-Physical Systems
    Kreimel, Philipp
    Eigner, Oliver
    Tavolato, Paul
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2017), 2017,
  • [9] An unsupervised anomaly-based detection approach for integrity attacks on SCADA systems
    Almalawi, Abdulmohsen
    Yu, Xinghuo
    Tari, Zahir
    Fahad, Adil
    Khalil, Ibrahim
    COMPUTERS & SECURITY, 2014, 46 : 94 - 110
  • [10] A new online anomaly learning and detection for large-scale service of Internet of Thing
    JunPing Wang
    Qiuming Kuang
    ShiHui Duan
    Personal and Ubiquitous Computing, 2015, 19 : 1021 - 1031