首页    期刊浏览 2024年10月06日 星期日
登录注册

文章基本信息

  • 标题:Session Based Packet Marking and Auditing for Network Forensics
  • 本地全文:下载
  • 作者:Omer Demir ; Ping Ji ; Jinwoo Kim
  • 期刊名称:International Journal of Digital Evidence
  • 印刷版ISSN:1938-0917
  • 出版年度:2007
  • 卷号:6
  • 期号:01
  • 出版社:International Journal of Digital Evidence
  • 摘要:The widely acknowledged problem of reliably identifying the origin of network data has been the subject of many research works. Due to the nature of Internet Protocol, a source IP can be easily falsified which results in numerous problems, including the infamous denial of service attacks. In this paper, two light-weight novel approaches are proposed to solve this problem by providing simple and effective logging and IP-Traceback mechanism: Session Based Packet Logging (SBL) and SYN Based Packet Marking (SYNPM). The contribution of these schemes lies in the fact that they are easy to be implemented with little overhead and are practical under sensitive privacy regulations, since they do not need to access detailed contents of each individual communication session. Currently, SBL and SYNPM approaches support only TCP sessions.
国家哲学社会科学文献中心版权所有