Protocol-Independent Detection of Dictionary Attacks - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

Protocol-Independent Detection of Dictionary Attacks

Martin Drašar
  • Fonction : Auteur
  • PersonId : 994071

Résumé

Data throughput of current high-speed networks makes it prohibitively expensive to detect attacks using conventional means of deep packet inspection. The network behavior analysis seemed to be a solution, but it lacks in several aspects. The academic research focuses on sophisticated and advanced detection schemes that are, however, often problematic to deploy into the production. In this paper we try different approach and take inspiration from industry practice of using relatively simple but effective solutions. We introduce a model of malicious traffic based on practical experience that can be used to create simple and effective detection methods. This model was used to develop a successful proof-of-concept method for protocol-independent detection of dictionary attacks that is validated with empirical data in this paper.
Fichier principal
Vignette du fichier
978-3-642-40552-5_30_Chapter.pdf (169.48 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01497030 , version 1 (28-03-2017)

Licence

Paternité

Identifiants

Citer

Martin Drašar. Protocol-Independent Detection of Dictionary Attacks. 19th Open European Summer School (EUNICE), Aug 2013, Chemnitz, Germany. pp.304-309, ⟨10.1007/978-3-642-40552-5_30⟩. ⟨hal-01497030⟩
70 Consultations
83 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More