Kalman Filter Based DNS Cache Poisoning Attack Detection

被引:0
|
作者
Wu, Hao [1 ]
Dang, Xianglei [1 ]
Zhang, Liang [1 ]
Wang, Lidong [1 ]
机构
[1] CNCERT CC, Beijing, Peoples R China
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Detection for Domain Name Systems cache poisoning attack is investigated. We exploit the fact that when attack is happening, the entropies of the query packet IP addresses of the cache server will have a decrease, to detect the cache poisoning attack. We pay attention to the detection method for the case that the entropy sequence has nonstationary dynamic at normal cases. In order to handle the nonstationarity, we first model the entropy sequence by a state space equation, and then we utilize Kalman filter to implement the attack detection. The problem is discussed for single and distributed cache poisoning attack, respectively. For the single one, we use the measurement errors to detect the anomaly. Under distributed attack, we utilize the correlation variation of the prediction errors to detect the attack event and identify the attacked cache servers. An experiment is illustrated to verify the effectiveness of our presented method.
引用
收藏
页码:1594 / 1600
页数:7
相关论文
共 50 条
  • [31] Adaptive Detection Technique for Cache-Based Side Channel Attack Using Bloom Filter for Secure Cloud
    Chouhan, Munish
    Hasbullah, Halabi
    2016 3RD INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION SCIENCES (ICCOINS), 2016, : 293 - 297
  • [32] A Poisoning Attack on Intrusion Detection System Based on SVM
    Qian Y.-G.
    Lu H.-B.
    Ji S.-L.
    Zhou W.-J.
    Wu S.-H.
    Lei J.-S.
    Tao X.-X.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2019, 47 (01): : 59 - 65
  • [33] APT Attack Detection Scheme Based on CK Sketch and DNS Traffic
    Xue, Defan
    Chi, Yaping
    Wu, Bing
    Zhao, Lun
    SENSORS, 2023, 23 (04)
  • [34] Dynamic load altering attack detection in smart grid based on multiple fading factor adaptive Kalman Filter
    Li, Jian
    Wang, Yunfeng
    Su, Qingyu
    ELECTRIC POWER SYSTEMS RESEARCH, 2023, 225
  • [35] Unscented Kalman Filter based interval state estimation of cyber physical energy system for detection of dynamic attack
    Wang, Huaizhi
    Meng, Anjian
    Liu, Yitao
    Fu, Xueqian
    Cao, Guangzhong
    ENERGY, 2019, 188
  • [36] DNS Cache-Based User Tracking
    Klein, Amit
    Pinkas, Benny
    26TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2019), 2019,
  • [37] Cache attack detection in virtualized environments
    Tank, Darshan
    Aggarwal, Akshai
    Chaubey, Nirbhay
    JOURNAL OF INFORMATION & OPTIMIZATION SCIENCES, 2019, 40 (05): : 1109 - 1119
  • [38] A Distributed Security Approach against ARP Cache Poisoning Attack
    Nobakht, Mehdi
    Mahmoudi, Hadi
    Rahimzadeh, Omid
    CYSSS'22: PROCEEDINGS OF THE 1ST WORKSHOP ON CYBERSECURITY AND SOCIAL SCIENCES, 2022, : 27 - 32
  • [39] A STATISTICAL EDGE DETECTION ALGORITHM BASED ON KALMAN FILTER
    You, Lihua
    Wu, Jingjing
    Cao, Yi
    JOURNAL OF INVESTIGATIVE MEDICINE, 2014, 62 (08) : S27 - S28
  • [40] A Kalman Filter Based Method for GPS Spoofing Detection
    Chen, Hao
    Fan, H. Howard
    PROCEEDINGS OF THE 2016 INTERNATIONAL TECHNICAL MEETING OF THE INSTITUTE OF NAVIGATION, 2016, : 151 - 159