• DocumentCode
    3236493
  • Title

    A flow-based method for abnormal network traffic detection

  • Author

    Kim, Aiyung-Sup ; Hun-Jeong Kong ; Seong-Cheol Hong ; Chung, Seung-Hwa ; Hong, J.W.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., POSTECH, South Korea
  • Volume
    1
  • fYear
    2004
  • fDate
    23-23 April 2004
  • Firstpage
    599
  • Abstract
    One recent trend in network security attacks is an increasing number of indirect attacks which influence network traffic negatively, instead of directly entering a system and damaging it. In future, damages from this type of attack are expected to become more serious. In addition, the bandwidth consumption by these attacks influences the entire network performance. This paper presents an abnormal network traffic detecting method and a system prototype. By aggregating packets that belong to the identical flow, we can reduce processing overhead in the system. We suggest a detecting algorithm using changes in traffic patterns that appear during attacks. This algorithm can detect even mutant attacks that use a new port number or changed payload, while signature-based systems are not capable of detecting these types of attacks. Furthermore, the proposed algorithm can identify attacks that cannot be detected by examining only single packet information.
  • Keywords
    Internet; computer network management; monitoring; packet switching; performance evaluation; telecommunication security; telecommunication traffic recording; Internet; abnormal network traffic detection; bandwidth consumption; changed payload; flow-based method; identical flow; indirect attacks; mutant attacks; network performance; network security attacks; new port number; packet aggregation; processing overhead reduction; traffic analysis; traffic monitoring; traffic pattern changes; Bandwidth; Computer crime; Computer science; Delay; Detection algorithms; IP networks; Information security; Payloads; Prototypes; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium, 2004. NOMS 2004. IEEE/IFIP
  • Conference_Location
    Seoul, South Korea
  • ISSN
    1542-1201
  • Print_ISBN
    0-7803-8230-7
  • Type

    conf

  • DOI
    10.1109/NOMS.2004.1317747
  • Filename
    1317747