Network attack detection at flow level

  • Authors:
  • Aleksey A. Galtsev;Andrei M. Sukhov

  • Affiliations:
  • Samara State Aerospace University, Samara, Russia;Samara State Aerospace University, Samara, Russia

  • Venue:
  • NEW2AN'11/ruSMART'11 Proceedings of the 11th international conference and 4th international conference on Smart spaces and next generation wired/wireless networking
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we propose a new method for detecting unauthorized network intrusions, based on a traffic flow model and Cisco NetFlow protocol application. The method developed allows us not only to detect the most common types of network attack (DDoS and port scanning), but also to make a list of trespassers' IP-addresses. Therefore, this method can be applied in intrusion detection systems, and in those systems which lock these IP-addresses.