DocumentCode :
1954637
Title :
Strategic deployment of network monitors for attack attribution
Author :
Pyun, Young June ; Reeves, Douglas S.
Author_Institution :
Department of Computer Science, North Carolina State University, Raleigh, 27695, USA
fYear :
2007
fDate :
10-14 Sept. 2007
Firstpage :
525
Lastpage :
534
Abstract :
Attacks launched over the Internet have become a pressing problem. Attackers make use of a variety of techniques to anonymize their traffic, in order to escape detection and prosecution. Despite much research on attack attribution, there has been little work on optimizing the number and placement of monitoring points for identifying the source of attacks with minimum ambiguity. This paper proposes such a method. The approach is based on the concept of graph separators. A separator partitions a network, such that the size of the separator is the number of monitors needed, and the size of a partition is the ambiguity in isolating the specific source of an attack. To achieve a desired degree of ambiguity, a good separator for the Internet is sought. Both vertex and edge separator heuristics are presented, which greedily select vertices of highest/lowest degree as monitors. The methods are evaluated for the Internet autonomous system (AS) topology. Experimental results show that the vertex separator heuristic requires just 5% of the ASes to be monitored to identify the source of an attack with little ambiguity. If only those links actually used for routing to a specific destination are considered, use of an edge separator requires 30% of the links to be monitored to achieve similar results. The results can be further improved if it is known that ASes have unequal probabilities of being the source of an attack.
Keywords :
Computer displays; Computer science; Cryptography; IP networks; Internet; Monitoring; Particle separators; Routing protocols; Safety; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Broadband Communications, Networks and Systems, 2007. BROADNETS 2007. Fourth International Conference on
Conference_Location :
Raleigh, NC, USA
Print_ISBN :
978-1-4244-1432-1
Electronic_ISBN :
978-1-4244-1433-8
Type :
conf
DOI :
10.1109/BROADNETS.2007.4550478
Filename :
4550478
Link To Document :
بازگشت