作者
Rick Hofstede, Václav Bartoš, Anna Sperotto, Aiko Pras
发表日期
2013/10/14
研讨会论文
Proceedings of the 9th International Conference on Network and Service Management (CNSM 2013)
页码范围
227-234
出版商
IEEE
简介
DDoS attacks bring serious economic and technical damage to networks and enterprises. Timely detection and mitigation are therefore of great importance. However, when flow monitoring systems are used for intrusion detection, as it is often the case in campus, enterprise and backbone networks, timely data analysis is constrained by the architecture of NetFlow and IPFIX. In their current architecture, the analysis is performed after certain timeouts, which generally delays the intrusion detection for several minutes. This paper presents a functional extension for both NetFlow and IPFIX flow exporters, to allow for timely intrusion detection and mitigation of large flooding attacks. The contribution of this paper is threefold. First, we integrate a lightweight intrusion detection module into a flow exporter, which moves detection closer to the traffic observation point. Second, our approach mitigates attacks in near real-time by …
引用总数
20132014201520162017201820192020202120222023202427411973116944
学术搜索中的文章
R Hofstede, V Bartoš, A Sperotto, A Pras - Proceedings of the 9th International Conference on …, 2013