Title :
Similarity coefficient generators for network forensics
Author :
Telidevara, A. ; Chandrasekaran, V. ; Srinivasan, A. ; Mukkamala, R. ; Gampa, S.
Author_Institution :
Sri Sathya Sai Inst. of Higher Learning, Anantapur, India
Abstract :
IP spoofing is one of the most common network threats today. While current IP Traceback techniques are capable of identifying the source of a message, they are limited by the huge number of messages that routers have to store to provide this facility. One way to reduce the storage overhead is to store the messages as indices in a Bloom filter. Current systems use Bloom filters at a router to know if a given message has gone through that router. However, often there is a need to know if a similar message has traversed through the router. This calls for similarity measures in the context of Bloom filters. In this paper, we develop such similarity measures (coefficients) in the context of two specialized Bloom filters-Hierarchical Bloom filter (HBF) and Winnowing Block Shingling (WBS). We compare the efficacy of these similarity measures with the Jaccard similarity coefficient. Simulations were carried out to evaluate the measures. The results indicate that HBF-measure is an optimistic metric and WBS-similarity is a pessimistic measure. Jaccard measure falls between the two. We propose a weighted metric that combines all the metrics and is more flexible than the individual measures.
Keywords :
IP networks; computer network security; message switching; telecommunication network routing; IP spoofing; IP traceback techniques; Jaccard similarity coefficient; Winnowing Block Shingling; hierarchical Bloom filter; message source; message storage; network forensics; network threats; router; similarity coefficient generators; Arrays; Context; Generators; IP networks; Payloads; Size measurement; FOR-CLAS; MOD-PERF; SEC-NETW;
Conference_Titel :
Information Forensics and Security (WIFS), 2010 IEEE International Workshop on
Conference_Location :
Seattle, WA
Print_ISBN :
978-1-4244-9078-3
DOI :
10.1109/WIFS.2010.5711462