Title of article :
HOST BASED INTERNET PROTOCOL (IP) PACKET ANALYSIS TO ENHANCE NETWORK SECURITY
Author/Authors :
AHMAD، T. نويسنده , , AHMAD، S.Z. نويسنده , , AHMAD، Z. نويسنده , , YASIN، M.M. نويسنده ,
Issue Information :
فصلنامه با شماره پیاپی سال 2007
Abstract :
Data communication in a computer network environment is facing serious security threats from numerous sources such as viruses, worms, Zombies etc. These threats can be broadly characterized as internal or external security threats. Internal threats are mainly attributed to sneaker-nets, utility modems and unauthorized users, which can be minimized by skillful network administration, password management and optimum usage policy definition. The external threats need more serious attention as these attacks are mostly coming from public networks such as Internet. Frequency and complexity of such attacks is much higher as compared to internal attacks. This paper presents a host based network layer screening of external and internal IP packets for logging, analyzing and real-time detection of possible IP spoofing and Denial of Service attacks. This work can also be used in tuning security rules definition for gateway firewalls. Software has been developed which intercepts IP traffic and analyses it with respect to integrity and origin of IP packet. The received IP packets are parsed and analyzed for possible signs of intrusion. The results show that by watching and categorizing composition of various transport protocol such as TCP, UDP, ICMP and others alongwith verifying the origin of received IP packet can help in devising real-time firewall rule and blocking possible external attack. This is highly desirable for fighting against zero day attacks and can result in a better Mean Time between Failures (MTBF) to increase the survivability of computer network. Used in a right context, packet screening and filtering can be a useful tool for provision of reliable and stable network services.
Keywords :
Internet protocol (IP) , DNS spoofing , Denial of service (DoS) , Distributed denial of service (DDoS) , network security , PACKET FILTERING , IP spoofing
Journal title :
A Quarter Scientific Journal of Pakistan Atomic Energy Commission
Journal title :
A Quarter Scientific Journal of Pakistan Atomic Energy Commission