An SNMP MIB oriented approach based on causality in network behavior is presented in order to detect attack before the security of target is damaged. According to the behavior of an abnormal variable in target
Granger causality test(GCT)is used to find preliminary attacking variables which are causality relevant to the abnormal variable in whole network behavior. Depending on the behavior features hidden in the abnormal behavior
GCT is used again to recognize attacking variables which are causality relevant to the abnormal variable in local network behavior. The causality between attacking variables and the abnormal variable is then used to construct detecting rules
which are oriented to attacker. udpOutDatagrams acting as attacking variable are recognized successfully and detection results are acquired well in the test of Trin00 UDP Flood. The experiment results show that the approach can effectively detect attacks from attackers
which has effect on blocking the pervasion of attacking procedure to target.
关键词
Keywords
references
THOTTAN M, JI Chuanyi. Anomaly detection in IP networks[J]. IEEE Trans on Signal Processing, 2003,51(8):2191-2204.
CABRERA J B D, LEWIS L, QIN Xinzhou. Proactive detection of distributed denial of service attacks using MIB traffic variables:a feasibility study [J]. IEEE Trans on Signal Processing, 2001,49(6):609-622.
WANG Sheng, SUN Lechang, GAN Guozheng. Application research based on Granger causality test for attack detection [J]. Computer Applications, 2005, 25(6):1282-1285.
邹柏贤,姚志强. 一种网络流量平稳化方法 [J]. 通信学报, 2004,25(8):14-23.
ZOU Baixian, YAO Zhiqiang. A method to stabilize network traffic [J]. Journal of China Institute of Communications, 2004,25(8):14-23.
HAMILTON J. Time series analysis [M]. Princeton, NJ, USA: Princeton University Press, 1994.
CRISCUOLO P J. Distribution denial of service: trin00, tribe flood network, gribe flood network 2000, and stacheldraht, CIAC-2319 [R]. Washington DC,USA: Computer Incident Advisory Capacity, Department of Energy, 2000.