년 - 년
Netflow를 활용한 대규모 서비스망 불법 접속 추적 모델 연구 KCI 등재
한국융합보안학회 융합보안논문지 제21권 제2호 2021.06 pp.11-18
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
대다수의 기업은 유무형의 자산을 보호하기 위한 방안으로, IT서비스망에 다양한 보안 장비를 구축하여 정보보호 모니터링 을 수행하고 있다. 그러나 서비스 망 고도화 및 확장 과정에서 보안 장비 투자와 보호해야 할 자산이 증가하면서 전체 서비스 망에 대한 공격 노출 모니터링이 어려워지는 한계가 발생하고 있다. 이에 대응하기 위한 방안으로 외부자의 공격과 장비 불법 통신을 탐지할 수 있는 다양한 연구가 진행되었으나, 대규모 서비스망에 대한 효과적인 서비스 포트 오픈 감시 및 불법 통신 모니터링 체계 구축에 대한 연구는 미진한 편이다. 본 연구에서는 IT서비스망 전체 데이터 흐름의 관문이 되는 네트워크 백본 장비의 ‘Netflow 통계 정보’를 분석하여, 대규모 투자 없이 광범위한 서비스망의 정보 유출 및 불법 통신 시도를 감시할 수 있 는 프레임워크를 제안한다. 주요 연구 성과로는 Netflow 데이터에서 운영 장비의 텔넷 서비스 오픈 여부를 6개의 ML 머신러 닝 알고리즘으로 판별하여 분류 정확도 F1-Score 94%의 높은 성능을 검증하였으며, 피해 장비의 불법 통신 이력을 연관하여 추적할 수 있는 모형을 제안하였다.
To protect tangible and intangible assets, most of the companies are conducting information protection monitoring by using various security equipment in the IT service network. As the security equipment that needs to be protected increases in the process of upgrading and expanding the service network, it is difficult to monitor the possible exposure to the attack for the entire service network. As a countermeasure to this, various studies have been conducted to detect external attacks and illegal communication of equipment, but studies on effective monitoring of the open service ports and construction of illegal communication monitoring system for large-scale service networks are insufficient. In this study, we propose a framework that can monitor information leakage and illegal communication attempts in a wide range of service networks without large-scale investment by analyzing ‘Netflow statistical information’ of backbone network equipment, which is the gateway to the entire data flow of the IT service network. By using machine learning algorithms to the Netfllow data, we could obtain the high classification accuracy of 94% in identifying whether the Telnet service port of operating equipment is open or not, and we could track the illegal communication of the damaged equipment by using the illegal communication history of the damaged equipment.
A Small-time Scale Netflow-based Anomaly Traffic Detecting Method Using MapReduce SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.2 2014.03 pp.231-242
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Anomaly traffic detecting using Netflow data is one of important problems in the field of network security. In this paper, we proposed an approach using MapReduce model, which was realized by means of the entropy observation and DFN (Distinct feature number) distribution deviations of traffic features under anomalies at small time scales. The MapReduce was used to deal with huge amounts of data with the aid of computer cluster processing. Experimental results show the effectiveness of the proposed approach.
A VoIP Traffic Monitoring System based on NetFlow v9
보안공학연구지원센터(IJAST) International Journal of Advanced Science and Technology vol.4 2009.03 pp.1-8
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
With the development of VoIP (Voice over IP) service, new security threats are expected to be appeared. However, existing IP network security solutions can not detect new VoIP specified network threats because they can not reflect characteristics of VoIP. In this paper, we propose a novel system that can monitor VoIP service and detect VoIP network threats practically. The proposed system collects attributes of VoIP traffic based on NetFlow, and executes monitoring and detecting based on statistic and behavior.
Netflow 트래픽을 이용한 분산 서비스거부 공격 탐지 기법
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2003 pp.1957-1960
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 분산 서비스거부 공격에 의한 특정 서버의 기능 마비, 더 나아가 네트워크 전체를 마비시키는 사례가 증가하고 있다. 이로 인한 피해의 심각성을 고려해 볼 때 적절한 대응이 시급한 실정이지만, 공격 특성상 공격을 탐지해 내기가 어렵다는 문제점이 있다. 본 논문에서는 분산 서비스거부 공격의 패턴을 파악하여 공격을 효과적으로 탐지할 수 있는 방법을 제안하였다. 공격 패턴 파악을 위해서 시스코사에서 개발한 Netflow 데이터를 이용하여 트래픽을 분석하고, 그 결과로 분산 서비스거부 공격의 효과적인 탐지에 공헌도가 큰 속성들을 추출하였다. 실제 인터넷 망에 연결된 라우터에서 수집한 Netaow 데이터와 분석에 의해 추출된 속성을 기반으로 데이터 마이닝 기술을 이용하여 공격 탐지의 성능을 측정하였다.
기간망에서 NetFlow를 이용한 하이브리드 유해 트래픽 제어 기법
[NRF 연계] 한국엔터테인먼트산업학회 한국엔터테인먼트산업학회논문지 Vol.4 No.1 2010.03 pp.38-46
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
현재 유해트래픽을 이용한 백본 네트워크를 경유하여 침해사고가 빈번하게 발생하고 있으며, 이에 응대하기 위한 방법 또한 활발하게 진행되고 있으나 보안 장비 도입에 따른 비용 증가와 관리에 따른 부담이 가중되고 있는 실정이다. 이에 본 논문에서는 기존의 백본 네트워크 구성 장비를 토대로 발생된 플로우 데이터를 수집하여 유해 트래픽으로부터 특정 서비스 IP나 포트 제어를 통해 백본 네트워크의 안전한 트래픽 환경을 유지하고, 추가 비용없이 기 구성된 환경을 토대로 혼합형 제어 기법을 적용하여 신속하게 유해 트래픽을 제어하여 보다 능동적으로 백본 네크워크를 유기적으로 관리할 수 있도록 하였다.
Currently, attacks by harmful traffics via backbone network occur frequently and countermeasure is being actively discussed. However, it’s a reality that the cost for introduction/management of security equipment is being increased. Therefore, this thesis proposes the way of proactive backbone network management, collecting flow data from existing backbone network component, maintaining safe traffic environment of backbone over the control of port and specific service IP from harmful traffic, and controlling harmful traffic immediately by applying hybrid control techniques based on customized environment without extra cost.
NetFlow 데이터를 이용한 실시간 네트워크 트래픽 어노멀리 검출 기법
[Kisti 연계] 한국정보처리학회 정보처리학회논문지 C Vol.c12 No.1 2005 pp.19-28
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 알려지지 않은 공격(unknown attack)으로부터 네트워크를 보호하기 위한 네트워크 트래픽 어노멀리(anomaly) 검출에 대한 관심이 고조되고 있다. 본 논문에서는 캠퍼스 네트워크의 보드라우터(border router)의 NetFlow 데이터로 제공되는 초당비트수(bits per second)와 초당플로수(flows per second)의 상관관계를 단순회귀분석을 통하여 새로운 어노멀리 검출 기법을 제시하였다. 새로이 제안된 기법을 검증하기 위해 실지 캠퍼스 네트워크에 적용하였으며 그 결과론 Holt-Winters seasonal(HWS) 알고리즘과 비교하였다. 특히, 제안된 기법은 기존 RRDtool에 통합시켜 실시간 검출이 가능하도록 설계하였다.
Recently, it has been sharply increased the interests to detect the network traffic anomalies to help protect the computer network from unknown attacks. In this paper, we propose a new anomaly detection scheme using the simple linear regression analysis for the exported LetFlow data, such as bits per second and flows per second, from a border router at a campus network. In order to verify the proposed scheme, we apply it to a real campus network and compare the results with the Holt-Winters seasonal algorithm. In particular, we integrate it into the RRDtooi for detecting the anomalies in real time.
[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.21 No.7 2016 pp.1-8
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Nowadays, distributed denial of service (DDoS) attacks on web sites reward attackers financially or politically because our daily lifes tightly depends on web services such as on-line banking, e-mail, and e-commerce. One of DDoS attacks to web servers is called HTTP-GET flood attack which is becoming more serious. Most existing techniques are running on the application layer because these attack packets use legitimate network protocols and HTTP payloads; that is, network-level intrusion detection systems cannot distinguish legitimate HTTP-GET requests and malicious requests. In this paper, we propose a practical detection technique against HTTP-GET flood attacks, based on the access behavior of inline objects in a webpage using NetFlow data. In particular, our proposed scheme is working on the network layer without any application-specific deep packet inspections. We implement the proposed detection technique and evaluate the ability of attack detection on a simple test environment using NetBot attacker. Moreover, we also show that our approach must be applicable to real field by showing the test profile captured on a well-known e-commerce site. The results show that our technique can detect the HTTP-GET flood attack effectively.
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.33 No.6 2023 pp.1033-1042
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문은 네트워크에서 침입 행위를 하는 플로우를 탐지하는 네트워크 침입 탐지 시스템을 제안한다. 대다수 연구에 활용되는 데이터세트는 시계열 정보를 포함하고 있지 않으며, 공격 사례가 적은 공격은 샘플 데이터 수가 부족해 탐지율 향상이 어렵다. 하지만 탐지 방안에 대해 연구 결과가 부족한 상황이다. 본 연구에서는 ANN(Artificial Neural Network) 모델과 스택 앙상블 기법을 활용한 선행 연구를 토대로 하였다. 앞서 언급한 문제점을 해결하기 위해 인접 플로우를 활용하여 시계열 정보를 추가하고 희소 공격의 샘플을 강화하여 학습하여 탐지율을 보강하였다.
This paper proposes a network intrusion detection system that identifies abnormal flows within the network. The majority of datasets commonly used in research lack time-series information, making it challenging to improve detection rates for attacks with fewer instances due to a scarcity of sample data. However, there is insufficient research regarding detection approaches. In this study, we build upon previous research by using the Artificial neural network(ANN) model and a stack ensemble technique in our approach. To address the aforementioned issues, we incorporate temporal information by leveraging adjacent flows and enhance the learning of samples from sparse attacks, thereby improving both the overall detection rate and the detection rate for sparse attacks.
넷플로우-타임윈도우 기반 봇넷 검출을 위한 오토엔코더 실험적 재고찰
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.33 No.4 2023 pp.687-697
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
공격 양상이 더욱 지능화되고 다양해진 봇넷은 오늘날 가장 심각한 사이버 보안 위협 중 하나로 인식된다. 본 논문은 UGR과 CTU-13 데이터 셋을 대상으로 반지도 학습 딥러닝 모델인 오토엔코더를 활용한 봇넷 검출 실험결과를 재검토한다. 오토엔코더의 입력벡터를 준비하기 위해, 발신지 IP 주소를 기준으로 넷플로우 레코드를 슬라이딩 윈도우 기반으로 그룹화하고 이들을 중첩하여 트래픽 속성을 추출한 데이터 포인트를 생성하였다. 특히, 본 논문에서는 동일한 흐름-차수(flow-degree)를 가진 데이터 포인트 수가 이들 데이터 포인트에 중첩된 넷플로우 레코드 수에 비례하는 멱법칙(power-law) 특징을 발견하고 실제 데이터 셋을 대상으로 97% 이상의 상관계수를 제공하는 것으로 조사되었다. 또한 이러한 멱법칙 성질은 오토엔코더의 학습에 중요한 영향을 미치고 결과적으로 봇넷 검출 성능에 영향을 주게 된다. 한편 수신자조작특성(ROC)의 곡선아래면적(AUC) 값을 사용해 오토엔코더의 성능을 검증하였다.
Botnets, whose attack patterns are becoming more sophisticated and diverse, are recognized as one of the most serious cybersecurity threats today. This paper revisits the experimental results of botnet detection using autoencoder, a semi-supervised deep learning model, for UGR and CTU-13 data sets. To prepare the input vectors of autoencoder, we create data points by grouping the NetFlow records into sliding windows based on source IP address and aggregating them to form features. In particular, we discover a simple power-law; that is the number of data points that have some flow-degree is proportional to the number of NetFlow records aggregated in them. Moreover, we show that our power-law fits the real data very well resulting in correlation coefficients of 97% or higher. We also show that this power-law has an impact on the learning of autoencoder and, as a result, influences the performance of botnet detection. Furthermore, we evaluate the performance of autoencoder using the area under the Receiver Operating Characteristic (ROC) curve.
대규모 넷플로우 데이터 분석을 위한 룰 기반 맵리듀스 아키텍쳐
[Kisti 연계] 한국정보과학회 정보과학회논문지:정보통신 Vol.40 No.6 2013 pp.303-311
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
넷플로우는 가장 보편적인 네트워크 트래픽 모니터링 및 분석을 위한 축약 기술로서 다양한 분석 툴들이 개발되어 왔다. 본 논문에서는 대규모 넷플로우에 대한 다양한 분석을 위하여 하둡 분산환경에서의 플로우 통계과 이상탐지를 위한 단일의 맵리듀스 룰 구조를 설계하고, 이를 이용한 분석과 침입탐지의 맵리듀스 방법을 제안한다. 본 논문에서 제안한 룰 기반 플로우 분석 방법의 범용성을 검증하기 위하여 대규모 네트워크 모니터링을 위한 CERT NetSA의 보안 툴인 SiLK 룰으로의 변환방법을 제시한다. 실험을 통해 우리가 제안한 룰 기반의 분석 방법이 시스템의 처리성능과 분석기능의 확장을 쉽게 달성할 수 있음을 확인한다. 본 연구는 하둡 기반의 IDS 시스템을 위한 토대로서, 향후 하둡 클러스터를 이용한 통합 네트워크 보안 솔루션으로 발전할 수 있을 것으로 기대한다.
NetFlow has been widely adopted for network monitoring and analysis. In this paper, we propose a MapReduce-oriented rule structure for calculating statistics and detecting anomalies from NetFlow data, and present a unified MapReduce job architecture for one-pass analytics using rulesets. By applying our proposal to the SiLK, a CERT NetSA security suite for large-scale network monitoring we show that our rule-based MapReduce approach is easily deployed for managing lots of flow data. From the evaluation with a Hadoop testbed, we confirm that our rule-based MapReduce approach is a scalable and practical solution for analyzing a large volume of NetFlow.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.