Detecting network intrusions via a statistical analysis of network packet characteristics
- 13 November 2002
- proceedings article
- Published by Institute of Electrical and Electronics Engineers (IEEE)
- p. 309-314
- https://doi.org/10.1109/ssst.2001.918537
Abstract
With the growing threat of abuse of network resources, it be- comes increasingly important to be able to detect malformed packets on a network and estimate the damage they can cause. Carefully constructed, certain types of packets can cause a victim host to crash while other pack- ets may be sent only to gather necessary information about hosts and net- works and can be viewed as a prelude to attack. In this paper, we collect and analyze all of the IP and TCP packets seen on a network that ei- ther violate existing standards or should not appear in modern internets. Our goal is to determine what these suspicious packets mean and evaluate what proportion of such packets can cause actual damage. Thus, we divide unusual packets obtained during our experiments into several categories depending on the severity of their consequences, including indirect conse- quences as a result of information gathering, and show the results. The traces analyzed were gathered at Ohio University's main Internet link, providing a massive amount of statistical data.Keywords
This publication has 3 references indexed in Scilit:
- State of the Practice of Intrusion Detection TechnologiesPublished by Defense Technical Information Center (DTIC) ,2000
- Bro: a system for detecting network intruders in real-timeComputer Networks, 1999
- A high-performance network intrusion detection systemPublished by Association for Computing Machinery (ACM) ,1999