• DocumentCode
    575073
  • Title

    Method for one packet aggregation to prevent degradation of network´s performance

  • Author

    Kim, Sang Wan ; Kang, Dong Won ; Lee, Jun Kyung

  • Author_Institution
    Internet Res. Div., ETRI, Daejeon, South Korea
  • fYear
    2011
  • fDate
    Nov. 29 2011-Dec. 1 2011
  • Firstpage
    711
  • Lastpage
    714
  • Abstract
    A normal traffic includes a plurality of packets in the same session, while most attack traffic consists of single packets generated in a single session. This papar relates to a method for aggregating single packets in a single session capable of detecting packets as attack traffic if the amount of single packets is excessively increased in a single session, and aggregating the single packets into a single flow to thus prevent degradation of a network´s performance due to the attack traffic. If single packets in a single session are inputted, checking a single packet processing reference and selecting one among a packet processing threshold value (Las) for each autonomous system (AS), a packet processing threshold value (Lh) for each host, and an overall system packet processing threshold value (Ls); and if the amount of the single packets in a single session is lager than the selected packet processing threshold value, aggregating the single packets in the single session into a single flow. This paper provides a method and apparatus for aggregating single packets in a single session capable of detecting packets as attack traffic if the amount of single packets is excessively increased in a single session, and aggregating the single packets into a single flow to thus prevent degradation of a network´s performance due to the attack traffic.
  • Keywords
    Internet; computer network security; telecommunication traffic; Internet; attack traffic; autonomous system; network performance degradation; packet aggregation method; packet detection; single packet processing reference; system packet processing threshold value; Aggregates; Degradation; Internet; Intrusion detection; Monitoring; Performance evaluation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Sciences and Convergence Information Technology (ICCIT), 2011 6th International Conference on
  • Conference_Location
    Seogwipo
  • Print_ISBN
    978-1-4577-0472-7
  • Type

    conf

  • Filename
    6316709