NETWORKING 2011: 10th International IFIP TC 6 Networking by Jérôme François, Shaonan Wang, Radu State, Thomas Engel

By Jérôme François, Shaonan Wang, Radu State, Thomas Engel (auth.), Jordi Domingo-Pascual, Pietro Manzoni, Sergio Palazzo, Ana Pont, Caterina Scoglio (eds.)

The two-volume set LNCS 6640 and 6641 constitutes the refereed court cases of the tenth foreign IFIP TC 6 Networking convention held in Valencia, Spain, in could 2011. The sixty four revised complete papers awarded have been conscientiously reviewed and chosen from a complete of 294 submissions. The papers characteristic leading edge examine within the components of purposes and prone, subsequent new release net, instant and sensor networks, and community technology. the 1st quantity contains 36 papers and is equipped in topical sections on anomaly detection, content material administration, DTN and sensor networks, strength potency, mobility modeling, community technological know-how, community topology configuration, subsequent new release web, and direction diversity.

2 to be deleted due to the victim overload. – Popup spam: this kind of spam is similar of sending undesired Windows Messenger popups by using UDP port 1026 and 1027. Only one packet of 925 bytes is needed. The victims IP addresses do not highlight a regular pattern because two consecutive IP addresses have a gap of 200 addresses. The interarrivaltime is generally lower than 1 millisecond except every 200 flows where it is around 64 milliseconds and every 550 where it is 250 milliseconds. – SSH scan + TCP flood: the goal of TCP scan is to probe an SSH server by trying to log in.

We briefly present fundamental background information and present the anomaly detection part of the tool where we describe its main components. The more we describe the kernel function that has been used for the evaluation of Netflow records. In section 3 we describe the data set and the different attacks, used for the experiments and in section 4 we present our evaluation methods and discusses experimental results. Section 5 discusses related work and conclusions are given in section 6. 2 The Architecture of the Anomaly Detector In the following section, we present the architecture of our model.

The results are similar to those for the representative interval above, and the costs over the 8 bins are shown in Fig 3. We observe that attacking any of these indexes results in an entropy drop. The larger the probability the greater the decrease, and so the higher the camouflage cost. 24 L. Zhang and D. Veitch The above discussion is only an example. The same analysis is applicable to other concentrated attacks and detection based on other metrics. For example, a worm attack may use fixed source port numbers, resulting in significant changes in a few indices of the source port distribution.

