DOC PREVIEW
CMU CS 15744 - Lecture

This preview shows page 1-2-3 out of 8 pages.

Save
View full document
View full document
Premium Document
Do you want full access? Go Premium and unlock all 8 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 8 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 8 pages.
Access to all documents
Download any document
Ad free experience
Premium Document
Do you want full access? Go Premium and unlock all 8 pages.
Access to all documents
Download any document
Ad free experience

Unformatted text preview:

Slide 1MotivationProblem DefinitionLog-based TracebackChallengesProposed MethodSPIE InfrastructureDiscussionCarnegie Mellon UniversityU Kang1Hash-Based IP TracebackU KangComputer Science Department15-744 Computer NetworksCarnegie Mellon UniversityU Kang2MotivationOur network or hosts have been compromisedHow can we trace the attackers identity?Carnegie Mellon UniversityU Kang3Problem DefinitionIP traceback problemGiven packets of interest,1. Identify the source of the packets2. Construct an attack graph composed of the attack paths for attack packets that arrived at the victimAttack GraphCarnegie Mellon UniversityU KangLog-based TracebackRouters keep the log of packetsIf an attack occurs, routers are queried for attack packetsCarnegie Mellon UniversityU Kang5ChallengesC1: Minimizing CostStorage used to keep informationC2: AccuracyNo false negativeMinimize false positiveC3: Maintaining PrivacyA tracing system should not adversely impact the privacy of legitimate usersCarnegie Mellon UniversityU Kang6Proposed MethodSource Path Isolation Engine(SPIE)Audit traffic by storing 32-bit packet digests rather than the packets themselvesSolves “C1: Minimizing Cost”, “C3: Maintaining Privacy”Bloom Filters to Minimize False PositiveSolves “C2: Accuracy”Bloom Filter - add() - isMember()Carnegie Mellon UniversityU Kang7SPIE Infrastructure1. IDS detects an attack packet2. IDS issue a traceback request to STM3. STM asks all SCARS in its domain to poll their respective DGAs for the relevant traffic digests4. SCARs construct attack subgraphsSTM: Traceback ManagerSCAR: Collection and Reduction AgentsDGA: Data Generation AgentCarnegie Mellon UniversityU Kang8DiscussionDeployment: can the SPIE infrastructure be deployed over multiple ISPs?Memory Requirements?A core router with a max. capacity of 640M pkts/sec requires 23 GB for one minute’s


View Full Document

CMU CS 15744 - Lecture

Documents in this Course
Lecture

Lecture

25 pages

Lecture

Lecture

10 pages

Lecture

Lecture

10 pages

Lecture

Lecture

45 pages

Lecture

Lecture

48 pages

Lecture

Lecture

19 pages

Lecture

Lecture

97 pages

Lecture

Lecture

39 pages

Lecture

Lecture

49 pages

Lecture

Lecture

33 pages

Lecture

Lecture

21 pages

Lecture

Lecture

52 pages

Problem

Problem

9 pages

Lecture

Lecture

6 pages

03-BGP

03-BGP

13 pages

Lecture

Lecture

42 pages

lecture

lecture

54 pages

lecture

lecture

21 pages

Lecture

Lecture

18 pages

Lecture

Lecture

18 pages

Lecture

Lecture

58 pages

lecture

lecture

17 pages

lecture

lecture

46 pages

Lecture

Lecture

72 pages

Lecture

Lecture

44 pages

Lecture

Lecture

13 pages

Lecture

Lecture

22 pages

Lecture

Lecture

48 pages

lecture

lecture

73 pages

17-DNS

17-DNS

52 pages

Lecture

Lecture

10 pages

lecture

lecture

53 pages

lecture

lecture

51 pages

Wireless

Wireless

27 pages

lecture

lecture

14 pages

lecture

lecture

18 pages

Lecture

Lecture

16 pages

Lecture

Lecture

14 pages

lecture

lecture

16 pages

Lecture

Lecture

16 pages

Lecture

Lecture

37 pages

Lecture

Lecture

44 pages

Lecture

Lecture

11 pages

Lecture

Lecture

61 pages

Multicast

Multicast

61 pages

Lecture

Lecture

19 pages

Lecture

Lecture

81 pages

Lecture

Lecture

9 pages

Lecture

Lecture

6 pages

Lecture

Lecture

63 pages

Lecture

Lecture

13 pages

Lecture

Lecture

63 pages

Lecture

Lecture

50 pages

lecture

lecture

35 pages

Lecture

Lecture

47 pages

Lecture

Lecture

29 pages

Lecture

Lecture

92 pages

Load more
Download Lecture
Our administrator received your request to download this document. We will send you the file to your email shortly.
Loading Unlocking...
Login

Join to view Lecture and access 3M+ class-specific study document.

or
We will never post anything without your permission.
Don't have an account?
Sign Up

Join to view Lecture 2 2 and access 3M+ class-specific study document.

or

By creating an account you agree to our Privacy Policy and Terms Of Use

Already a member?