مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Persian Verion

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

video

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

sound

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Persian Version

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

View:

472
مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Download:

0
مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Cites:

Information Journal Paper

Title

Improving Payload Attribution Techniques in Computer Network Criminology with Time based Hierarchical Bloom Filter

Pages

  71-81

Abstract

 In the light of increased network attacks, Payload Attribution is an essential part of any forensics analysis of the attack. Usually attribution has to be done based on the payload of the packets. In such techniques network traffic should be stored in its entirety while user privacy is preserved. Bloom filters have been an ideal tool for such requirements. Previous works in this area have tried to minimize the false positive error rate associated with the bloom filter while improving on the data reduction ratio but there has not been any notable research on practical implementations in computer networks. A Payload Attribution technique should provide a list of connections which are suspects of carrying a specific payload (i. e. malware signature). The problem arises with the fact that there are too many queries required, given the large number of connections and the number of bloom filters involved over long time periods, which results in a large aggregate error rate. In this work, we propose a technique with which a time-based hierarchical bloom filter configuration is proposed to tackle the noted problem. Our evaluation shows that with this proposed technique we are able to limit the false positive error rate of the system as compared to the previously proposed techniques. This leads to an overall error reduction in the Payload Attribution system. More specifically, the error rate compared to previous work drops from 5. 66% to 3. 98% which results in reducing the number of incorrectly identified flows by 8400.

Cites

  • No record.
  • References

  • No record.
  • Cite

    APA: Copy

    Sasan, Z., & KHARAZI, M.. (2019). Improving Payload Attribution Techniques in Computer Network Criminology with Time based Hierarchical Bloom Filter. JOURNAL OF ELECTRONIC AND CYBER DEFENCE, 7(3 ), 71-81. SID. https://sid.ir/paper/358519/en

    Vancouver: Copy

    Sasan Z., KHARAZI M.. Improving Payload Attribution Techniques in Computer Network Criminology with Time based Hierarchical Bloom Filter. JOURNAL OF ELECTRONIC AND CYBER DEFENCE[Internet]. 2019;7(3 ):71-81. Available from: https://sid.ir/paper/358519/en

    IEEE: Copy

    Z. Sasan, and M. KHARAZI, “Improving Payload Attribution Techniques in Computer Network Criminology with Time based Hierarchical Bloom Filter,” JOURNAL OF ELECTRONIC AND CYBER DEFENCE, vol. 7, no. 3 , pp. 71–81, 2019, [Online]. Available: https://sid.ir/paper/358519/en

    Related Journal Papers

    Related Seminar Papers

  • No record.
  • Related Plans

  • No record.
  • Recommended Workshops






    Move to top
    telegram sharing button
    whatsapp sharing button
    linkedin sharing button
    twitter sharing button
    email sharing button
    email sharing button
    email sharing button
    sharethis sharing button