The Experts below are selected from a list of 32427 Experts worldwide ranked by ideXlab platform
G Padmavathi - One of the best experts on this subject based on the ideXlab platform.
-
malicious traffic detection and containment based on Connection Attempt failures using kernelized elm with automated worm containment algorithm
Indian journal of science and technology, 2016Co-Authors: S Divya, G PadmavathiAbstract:Objectives: In the world of Internet today, most of the communications are done through Internet applications. Rapidly with the growth of Internet, the security threat on Internet is also increasing. Internet worms are one of the serious dangerous threats heavy financial losses. To overcome these damages, the proposed methodology provide better defense mechanism through Internet worm detection and containment schemes based on Connection Attempt failures characteristic. Method: The Internet worm detection is done using the Machine Learning Method based on Anomaly detection schemes and containment based on blocking schemes. The proposed kernelized Extreme Learning Machine with Automated Worm Containment Algorithm (kEA) method is used for detection and containment of malicious traffic from non-existing IP addresses based on Connection Attempt failures. Findings: Second channel based propagation through botnet worms propagates illegal traffic from malicious IP addresses through Connection Attempt failures. This traffic is transferred through TCP and UDP transmission schemes. The proposed work is used to identify the second channel propagating worms and containment of malicious traffic. Improvement: The proposed kernelized Extreme Learning Machine (kELM) method achieved detection accuracy improved by 23.67%. Then proposed kEA method blocks all the detected malicious IP addresses with 100% containment at the time span of 33 ms.
Hyong S Kim - One of the best experts on this subject based on the ideXlab platform.
-
scanner detection based on Connection Attempt success ratio with guaranteed false positive and false negative probabilities
2006Co-Authors: Seung Yeob Nam, Hyong S KimAbstract:Since the link rate is very high up to 40Gbps these days, scanning packets can spread very fast. At this high speed, only a small chance of missing on-going scanning activity can lead to catastrophic results. Thus, fast and accurate detection of scanners is a very important problem. High-speed packet processing usually requires high-speed memory, SRAM, and the size of SRAM is very limited compared with DRAM. We propose a Connection Attempt success ratio based scanning detection scheme which guarantees false positive and false negative probabilities under a memory-limited environment. Our scheme can also detect slow scanners with guaranteed performance. A sampling-based extended version can overcome the limitation of short-history-based scanning detection schemes and detects enhanced scanners with a list of pre-acquired IP addresses with guaranteed performance. The proposed scheme reduces the required memory size from O(N) to O(N), where N is the number of active hosts. We apply Bloom filter in order to further reduce the memory size. We evaluate the performance of the proposed scheme through simulation.
Computer Science - One of the best experts on this subject based on the ideXlab platform.
-
Analysis of SSH attacks of Darknet using Honeypots
International Journal of Engineering Development and Research, 2014Co-Authors: Shaik Bhanu, Girish Khilari, Varun Kumar, Computer ScienceAbstract:-A Darknet is a private network and the Connections are made only between trusted friends. In the field of computer security, honeypot is an internet attached server that acts as a decoy, to trap the hackers in order to study their activities and monitor how they are able to break into a system. In this paper we present the results of SSH honeypot operations in which it undertook the web trap of attackers who target SSH service in order to gain illegal services. A medium interaction honeypot offers a high interaction level to the attacker and when a Connection Attempt is made to system port, the honeypot can reply back with specially crafted packets that emulate of a real network services. The fake system has remained online and fully operational, capturing attacks and logging all malicious activity. Lastly we collect the data and analyzed the information.
Mohammad S Obaidat - One of the best experts on this subject based on the ideXlab platform.
-
honeypots deployment for the analysis and visualization of malware activity and malicious Connections
International Conference on Communications, 2014Co-Authors: Ioannis Koniaris, G I Papadimitriou, Petros Nicopolitidis, Mohammad S ObaidatAbstract:Honeypots are systems aimed at deceiving threat agents. In most of the cases the latter are cyber attackers with financial motivations, and malicious software with the ability to launch automated attacks. Honeypots are usually deployed as either production systems or as research units to study the methods employed by attackers. In this paper we present the results of two distinct research honeypots. The first acted as a malware collector, a device usually deployed in order to capture self-propagating malware and monitor their activity. The second acted as a decoy server, dropping but logging every malicious Connection Attempt. Both of these systems have remained online for a lengthy period of time to study the aforementioned malicious activity. During this assessment it was shown that human attackers and malicious software are constantly attacking servers, trying to break into systems or spread across networks. It was also shown that the usage of honeypots for malware monitoring and attack logging can be very effective and provide valuable data. Lastly, we present an open source visualization tool which was developed to help security professionals and researchers during the analysis and conclusion drawing phases, for use with one of the systems fielded in our study.
S Divya - One of the best experts on this subject based on the ideXlab platform.
-
malicious traffic detection and containment based on Connection Attempt failures using kernelized elm with automated worm containment algorithm
Indian journal of science and technology, 2016Co-Authors: S Divya, G PadmavathiAbstract:Objectives: In the world of Internet today, most of the communications are done through Internet applications. Rapidly with the growth of Internet, the security threat on Internet is also increasing. Internet worms are one of the serious dangerous threats heavy financial losses. To overcome these damages, the proposed methodology provide better defense mechanism through Internet worm detection and containment schemes based on Connection Attempt failures characteristic. Method: The Internet worm detection is done using the Machine Learning Method based on Anomaly detection schemes and containment based on blocking schemes. The proposed kernelized Extreme Learning Machine with Automated Worm Containment Algorithm (kEA) method is used for detection and containment of malicious traffic from non-existing IP addresses based on Connection Attempt failures. Findings: Second channel based propagation through botnet worms propagates illegal traffic from malicious IP addresses through Connection Attempt failures. This traffic is transferred through TCP and UDP transmission schemes. The proposed work is used to identify the second channel propagating worms and containment of malicious traffic. Improvement: The proposed kernelized Extreme Learning Machine (kELM) method achieved detection accuracy improved by 23.67%. Then proposed kEA method blocks all the detected malicious IP addresses with 100% containment at the time span of 33 ms.