کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
454620 695249 2007 8 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Probabilistic analysis of an algorithm to compute TCP packet round-trip time for intrusion detection
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Probabilistic analysis of an algorithm to compute TCP packet round-trip time for intrusion detection
چکیده انگلیسی

Estimating the length of a connection chain is challenging and critical in detecting stepping-stone intrusion. In this paper, we propose a novel method, called standard deviation-based clustering approach (SDBA), to estimate the length of an interactive connection chain by computing round-trip time (RTT). SDBA takes advantage of RTTs distribution and inter-arrival distribution of “send” packets. We prove that the probability of making a correct selection of RTT through SDBA is bounded by 1 − (1/q2), where q is a number related to standard deviation of RTTs distribution and send packets inter-arrival distribution. Experimental results showed that SDBA can compete against the best known algorithm in packet-matching rate and accuracy. This paper also presents the restrictions of SDBA.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Security - Volume 26, Issue 2, March 2007, Pages 137–144
نویسندگان
, ,