년 - 년
Syn Flooding 탐지를 위한 효과적인 알고리즘 기법 비교 분석 KCI 등재
한국융합보안학회 융합보안논문지 제23권 제5호 2023.12 pp.73-79
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
사이버 위협은 기술의 발전에 따라 진화되고 정교해지고 있으며, DDoS 공격으로 인한 서비스 장애를 발생 이슈들이 증가하고 있다. 최근 DDoS 공격은 특정 서비스나 서버의 도메인 주소에 대량의 트래픽을 유입시켜 서비스 장애를 발 생시키는 유형이 많아지고 있다. 본 논문에서는 대역폭 소진 공격의 대표적인 공격 유형인 Syn Flooding 공격의 데이 터를 생성 후, 효과적인 공격 탐지를 위해 Random Forest, Decision Tree, Multi-Layer Perceptron, KNN 알고리즘을 사용하여 비교 분석하였고 최적의 알고리즘을 도출하였다. 이 결과를 토대로 Syn Flooding 공격 탐지 정책을 위한 기 법으로 효과적인 활용이 가능할 것이다.
Cyber threats are evolving and becoming more sophisticated with the development of new technologies, and consequently the number of service failures caused by DDoS attacks are continually increasing. Recently, DDoS attacks have numerous types of service failures by applying a large amount of traffic to the domain address of a specific service or server. In this paper, after generating the data of the Syn Flooding attack, which is the representative attack type of bandwidth exhaustion attack, the data were compared and analyzed using Random Forest, Decision Tree, Multi-Layer Perceptron, and KNN algorithms for the effective detection of attacks, and the optimal algorithm was derived. Based on this result, it will be useful to use as a technique for the detection policy of Syn Flooding attacks.
애드혹 네트워크에서 패킷 수신 횟수에 기반한 확률적 플러딩 알고리즘 KCI 등재
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제11권 제2호 2011.04 pp.197-203
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
애드 혹 네트워크는 네트워크의 구성 요소를 관리하는 AP가 없는 대신 각각의 노드가 라우팅 알고리즘에 의한 동작으로 노드간에 정보를 전송한다. 이 때 네트워크 내 모든 노드로 정보를 전송하는 브로드캐스팅 과정이 필수적이다. 브로드캐스팅 과정에서는 네트워크를 구성하는 노드에 대한 충분한 정보 없이 모든 노드로 패킷을 전송하므로 동일한 패킷의 중복 수신이 발생하며, 이는 네트워크의 전력 효율을 감소시키는 원인이 된다. 본 논문에서는 전송 효율을 증가시키기 위하여 패킷 수신 횟수에 의한 확률적 브로드캐스트 기법을 제안한다. 각 노드는 과거 패킷 수신 횟수에 근거하여 신뢰성이 보장된 범위 내에서 높은 전송 효율을 갖는 브로드캐스트 확률을 계산하고 이 확률에 따라 각 노드는 브로드캐스트를 수행한다. 본 논문에서는 모의 실험을 통하여 제안 기법의 성능을 검증하였다.
Ad-hoc networks do not rely on a preexisting infrastructure such as Access Points(AP) in wireless network infrastructure. Instead each node participates in routing by forwarding data for other nodes. It makes required broadcasting to transmit packets to the whole network. In that part, each node tries to transmit data without any information about the other nodes. Therefore it causes duplication of transmission and waste of power. This paper presents adaptive probabilistic broadcasting schemes based on packet reception counts to alleviate the broadcast storm problem for wireless ad hoc networks. In this algorithm, each node calculates efficiency broadcast probability. Simulation results for the proposed flood algorithm are also presented.
보안공학연구지원센터(IJUNESST) International Journal of u- and e- Service, Science and Technology Vol.8 No.1 2015.01 pp.267-276
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
To achieve network-wide time synchronization in multi-hop wireless sensor networks (WSN), this paper proposes an accurate and energy-balanced time synchronization algorithm based on flooding. Flooding Time-Synchronization Protocol (FTSP) has advanced features, such as implicitly dynamic topology and high time accuracy, which can't be affected by some node's losing. FTSP propagates its time information of the reference node without concern about the network topology. However, in large-scale WSN applications, the efficiency of FTSP will be reduced drastically because of serious network storm. Meanwhile, the energy consumption of the network breaks the energy balance. In this paper, our aim is to solve the problems of synchronization error accumulation and unbalanced energy consumption. Our theoretical findings and experimental results show that forbidding possibly invalid forwarding among the sensor nodes drastically improves the synchronization accuracy and performance of energy-balanced.
[Kisti 연계] 한국전자통신연구원 ETRI journal Vol.43 No.3 2021 pp.414-426
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In the task of data routing in Internet of Things enabled volatile underwater environments, providing better transmission and maximizing network communication performance are always challenging. Many network issues such as void holes and network isolation occur because of long routing distances between nodes. Void holes usually occur around the sink because nodes die early due to the high energy consumed to forward packets sent and received from other nodes. These void holes are a major challenge for I-UWSANs and cause high end-to-end delay, data packet loss, and energy consumption. They also affect the data delivery ratio. Hence, this paper presents an energy efficient watchman based flooding algorithm to address void holes. First, the proposed technique is formally verified by the Z-Eves toolbox to ensure its validity and correctness. Second, simulation is used to evaluate the energy consumption, packet loss, packet delivery ratio, and throughput of the network. The results are compared with well-known algorithms like energy-aware scalable reliable and void-hole mitigation routing and angle based flooding. The extensive results show that the proposed algorithm performs better than the benchmark techniques.
슈퍼피어를 이용한 모바일 P2P시스템을 위한 효율적인 플러딩 알고리즘
[Kisti 연계] 한국정보과학회 정보과학회논문지:컴퓨팅의 실제 및 레터 Vol.16 No.2 2010 pp.217-221
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
다양한 종류의 새로운 모바일 기기의 등장과 이들 기기들의 사용자의 증가에 따라 모바일 P2P 시스템과 관련된 연구가 활발히 진행되고 있다. 본 논문에서는 모바일 환경에서 double-layered 슈퍼 피어 시스템을 위한 새로운 검색 알고리즘을 제안한다. 제안한 검색 알고리즘에서는 전체 실험 영역을 그리드 셀로 분할하며 셀들은 같은 크기를 가지고 있다. 그리드는 모바일 기기의 통신 반경과 피어들의 수를 고려하여 적절히 구성된다. 제안한 검색 알고리즘은 방향 분할 플러딩으로서 검색시 셀들의 검색 방향을 포함하는 방법을 기반으로 한다. 이 방법은 성공적으로 네트워크의 부하를 줄였으나 낮은 검색 성공률을 보여준다. 성공률을 보다 개선하기 위해 슈퍼 피어를 위한 bridge-peer table과 n-way 검색을 활용하였다. 그 실험결과 제안한 알고리즘은 기존의 double-layered 시스템에 비하여 평균 20~30%의 메시지 패킷수가 감소되었음을 보여주었다. 성공률 역시 double-layered 시스템에 비해 약2~5% 개선되었다.
As the appearances of various new mobile devices and the explosive growth of mobile device users, many researches related to mobile P2P systems have been proceeded actively. In this paper, we propose a new search algorithm for the double-layered super peer system in the mobile environment. For the proposed search algorithm, we divide the entire experiment region into a grid of cells, each of which has the same size. The grid is configured properly by considering the communication range of a mobile device and the number of peers in the system. The proposed search algorithm is a partial flooding search method based on the directions of cells involved with the search. It reduces successfully the network traffic, but shows a low search hit ratio. To enhance the search hit ratio, we introduce a bridge-peer table for a super peer and utilize an n-way search. The experimental results show that the proposed algorithm made an average of 20~30% reduction in the number of message packets over the double-layered system. The success ratio was also improved about 2~5% over the double-layered system.
재전송 노드의 선택에 의한 효율적인 Flooding 알고리즘
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2007 pp.907-910
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 Ad-hoc 네트워크에서 패킷 flooding에 의해 발생하게 되는 broadcast storm problem [1]을 해결하기 위한 크로스 레이어 기반의 flooding 기법을 제안한다. 제안된 flooding 기법은 크로스 레이어 프로토콜을 기반으로 하여 물리계층과 MAC (Medium Access Control) 계층에서 이웃 노드들에 대한 정보를 수집하고, 이를 이용하여 효율적인 재전송 노드의 수를 결정한다. 모의 실험을 통한 성능평가에서는 전체 네트워크 노드에 대한 수신 비율이 simple flooding 에 근접하며, 전송 비율 및 평균중복패킷 수에서도 좋은 성능을 보임으로서 broadcast storm problem을 해결할 수 있다.
단일 플러딩 라우팅 알고리즘을 활용한 센서 네트워크의 시간 동기화 기법
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2009 pp.177-178
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
일반적으로 센서 네트워크는 라우팅 트리를 구축한 후에 시간 동기화를 수행한다. 이로 인하여 시간 동기화가 늦어지고 교환하는 패킷이 증가하여 에너지를 많이 소모하는 문제를 유발한다. 본 논문에서는 한 번의 플러딩 과정으로 라우팅 트리를 구축하고 시간 동기화를 이와 동시에 수행하는 알고리즘을 제안한다. 시뮬레이션에 의하여 제안하는 알고리즘은 기존의 동기화 알고리즘인 TPSN과 동등한 수준의 정확도를 보이면서 동기화 속도 및 에너지 소모 면에서 우수하다는 것을 입증하였다.
단일 플러딩 라우팅 알고리즘을 활용한 센서 네트워크의 시간 동기화 기법
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2009 pp.177-178
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
일반적으로 센서 네트워크는 라우팅 트리를 구축한 후에 시간 동기화를 수행한다. 이로 인하여 시간 동기화가 늦어지고 교환하는 패킷이 증가하여 에너지를 많이 소모하는 문제를 유발한다. 본 논문에서는 한 번의 플러딩 과정으로 라우팅 트리를 구축하고 시간 동기화를 이와 동시에 수행하는 알고리즘을 제안한다. 시뮬레이션에 의하여 제안하는 알고리즘은 기존의 동기화 알고리즘인 TPSN과 동등한 수준의 정확도를 보이면서 동기화 속도 및 에너지 소모 면에서 우수하다는 것을 입증하였다.
DDoS TCP Syn Flooding Backscatter 분석 알고리즘
[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.14 No.9 2009 pp.55-66
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 인터넷 보급으로 우리 생활 속에 급성장하여 널리 이용되고 있는 대형 포털 및 소셜 네트워크서비스를 공격하여 개인 고객의 데이터베이스를 가로채고 웹사이트의 정상적인 서비스를 방해하는 DDoS(Distribute Denial of Service Attack) 분산 서비스 공격에 대해 알아보고자 한다. 공격 유형중에 TCP SYN Flooding 공격은 많은 트래픽을 유발시키지 않으면서도 공격 형태가 정상적인 트랜잭션의 형태를 가지고 있으므로 공격에 대한 탐지가 쉽지 않다. 이에 대해 본 논문에서는 기존의 탐지방법은 False Alarm을 유발할 가능성을 많이 가지고 있으므로 이를 보다 정확하게 탐지하기 위한 방안을 모색하고 제안하고자 하며, Backscatter 현상을 탐지하여 TCP SYN Flooding 공격을 감지하는 알고리즘을 제안하고자 한다.
In this paper, I will discuss how the Internet has spread rapidly in our lives. Large portals and social networks experience service attacks that access personal customers' databases. This interferes with normal service through DDoS (Distribute Denial of Service Attack), which is the topic I want to discuss. Among the types of DDoS, TCP SYN Flooding attacks are rarely found because they use few traffics and its attacking type is regular transaction. The purpose of this study is to find and suggest the method for accurate detection of the attacks. Through the analysis of TCP SYN Flooding attacks, we find that these attacks cause Backscatter effect. This study is about the algorithm which detects the attacks of TCP SYN Flooding by the study of Backscatter effect.
EPA-SWMM과 지표수 흐름방향 결정 알고리즘을 결합한 도시침수 모형의 개발
[Kisti 연계] 한국수자원학회 한국수자원학회 학술대회논문집 2021 p.305
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
XP-SWMM은 EAP-SWMM의 Runoff 기능을 보완하고 2D 해석 기능을 새롭게 추가하여 만든 외산(XP Solutions) 프로그램으로 도시유역 유출량 산정, 우수관거 추적 등과 같은 모의가 가능한 종합 모형이다. 그 중 2차원 분석 기능(2D XP-SWMM)은 연산 결과를 Tu-Flow 모형에 대입한 도시침수 해석모형으로 실무에서 주로 사용되고 있다. 그러나 XP-SWMM은 수량 부분 외에도 수질 부분의 다양한 모형이 통합되어 있어 라이센스 가격이 상당히 높고, 국내 환경에 적합한 모형 수정 등 기술지원을 받기 어렵다는 단점을 갖고 있다. 또한, 실무 활용성이 높은 2차원 분석기능의 경우 모의에 소요되는 시간이 크다는 한계점을 갖고 있다. 2D XP-SWMM 연산의 소요시간이 큰 주요 원인은 계산 시간간격마다 큰 셀수의 행렬 계산을 반복하기 때문이며, 격자를 촘촘하게 설정할수록(행렬의 수가 증가할수록) 수치해석에 소요되는 시간은 기하급수적으로 늘어나게 된다. 2D XP-SWMM 연산은 편미분방정식을 계산하는 모형으로 반복법을 채택하고 있기 때문에 짧은 시간내에 침수해석을 진행해야하는 웹기반 초단기 홍수예경보 시스템 등에 활용하기에는 적합하지 않다. 본 연구에서는 2D XP-SWMM 보다 연산속도를 향상시킨 2차원 도시침수 모형을 개발하였다. 기존 XP-SWMM 중심의 실무 적용성을 유지하고자 XP-SWMM과 동일하게 EPA-SWMM 엔진을 활용하였고 DEM 기반의 지표수 흐름방향 결정 알고리즘을 결합하였다. 본 연구에서 개발한 도시침수 모형 결과를 울산광역시, 청주시 등 도심지에서 발생한 과거 침수피해의 양상과 비교하여 그 타당성을 검증하였다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.