DocumentCode
3092788
Title
Network Forensics in MANET: Traffic Analysis of Source Spoofed DoS Attacks
Author
Guo, Yinghua ; Simon, Matthew
Author_Institution
Sch. of Comput. & Inf. Sci., Univ. of South Australia, Adelaide, SA, Australia
fYear
2010
fDate
1-3 Sept. 2010
Firstpage
128
Lastpage
135
Abstract
The process of analyzing available network forensics evidence to determine their meaning and significance can be very involved. It is often necessary to develop a timeline of significant events to obtain an overview of what occurred, to create relational diagrams showing which users are connected to which systems, or to correlate and analyze data to find noteworthy patterns of network traffic. However, there is a lack of statistical analysis of network traffic for security incident determination, especially the Denial of Service (DoS) attack in mobile ad hoc network (MANET). In this work, we focus on the "analysis" part of network forensic investigation. Specifically, we study one type of DoS attack, called distributed DoS (DDoS) flooding attack in MANET. We present a quantitative model to characterizes this attack and its traffic statistics. We also propose an analytical model for looking for specific patterns of the attack traffic, aiming to achieve: (1) Determine if there is an anomaly in the traffic and whether the anomaly is the DDoS attack (2) Determine the time when the attack is launched.
Keywords
ad hoc networks; computer forensics; computer network reliability; mobile radio; statistical analysis; MANET; network forensics; security incident determination; source spoofed DoS attacks; statistical analysis; traffic analysis; Analytical models; Computer crime; Feature extraction; Forensics; Mobile ad hoc networks; Mobile communication; DDoS attack; MANET; network forensics; traffic analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and System Security (NSS), 2010 4th International Conference on
Conference_Location
Melbourne, VIC
Print_ISBN
978-1-4244-8484-3
Electronic_ISBN
978-0-7695-4159-4
Type
conf
DOI
10.1109/NSS.2010.45
Filename
5636104
Link To Document