Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Download now

Matching TCP/IP Packets to Detect Stepping-Stone Intrusion

PublisherUniversity of Houston
Format193.6KB PDFDate added01 Oct 2006
Topics TCP - IP, Intrusion Detection Systems
Downloads34

This paper proposes a "Step-Function" method to detect network attackers from using a long connection chain to hide their identities when they launch attacks. The objective of the method is to estimate the length of a connection chain based on the changes in packet round trip times. The key point to compute the round trip time of a connection chain is to match a Send and its corresponding Echo packet. The paper propose a conservative and a greedy matching algorithm to match TCP/IP packets in real-time. The first algorithm matches fewer packets but the quality of the matching is high. The second one matches more packets with some uncertainty on the correctness.

Download now

Did you find this white paper useful?
13 out of 35 users found this white paper useful


  • Trackback
  • Clip Link

Related white papers

Building Reliable IP Telephony Systems

Reliability is the most critical aspect of a business phone system. IP telephony systems will deliver differing service levels because their architecture is fundamentally different. Ironically, optimal architecture and design...


Cash In Your PBX -- Upgrade with Cisco. Gain significant new savings now

PBX systems and old telephony applications were just not built for today's business needs. They don't scale easily, struggle to support mobility, and are increasingly expensive to maintain. Now you...


IOS Tips and Tricks

There are a number of things you can do with Cisco's IOS to make your life easier. This white paper presents some ways that IOS commands can help streamline your...


Dell-Customized Mobility Solutions

The marketplace is overflowing with a multitude of mobility options for businesses of all types and sizes. From notebooks, netbooks, and handheld computers to WiFi, smartphones, and mobile broadband, there...


Interactive Guide: Enterprise Mobility

Getting Started With Enterprise Mobility: A Guide to Sybase's Enterprise Mobility Platform. With the broadest portfolio of industry-leading products, an innovative mobility platform that provides a foundation for future growth,...


Webcast & Video: Special Report on MEAP featuring research from Gartner

Complimentary Webcast: Taking a Strategic Approach to Enterprise Mobility. Whether you're just getting started with mobility or have already rolled out multiple applications, taking a strategic approach to mobility is...


BCube: A High Performance, Server-Centric Network Architecture for Modular Data Centers

This paper presents BCube, a new network architecture specifically designed for shipping-container based, modular data centers. At the core of the BCube architecture is its server-centric network structure, where servers...


Broadband Deals? Powered by Top 10 Broadband

150+ broadband packages

Compare 30+ mobile broadband deals

Mobile Broadband »
White Paper

Featured White Paper

Technical Description: IBMXIV Storage System

The IBMXIV® Storage System offers a new level of high-end disk system performance and reliability. It is a core component of theIBMInformation Infrastructure which helps clients address their needs for availability, security, compliance and retention of information. The XIVsystem provides consistency under all conditions, immunity to hotspots, ...

Download Now

Other White Papers

Best Practices for Translating Customer Satisfaction into Revenue

Today's support organisations are focused on two top-level metrics: financial results and customer...

Data Quality Considerations for a Master Data Management Structure

Companies acquiring companies. Human Resources sharing information with Finance. Businesses...

See All White Papers


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters