Repository logo
  • English
  • 中文
Log In
Have you forgotten your password?
  1. Home
  2. College of Electrical Engineering and Computer Science / 電機資訊學院
  3. Electrical Engineering / 電機工程學系
  4. Network Traffic Filtering: Using Stamps, Bitmaps, and Host Diversities
 
  • Details

Network Traffic Filtering: Using Stamps, Bitmaps, and Host Diversities

Date Issued
2007
Date
2007
Author(s)
Huang, Chun-Ying
DOI
en-US
URI
http://ntur.lib.ntu.edu.tw//handle/246246/53512
Abstract
As the maturity of Internet infrastructures, more and more hosts can be reached through the Internet. People now can enjoy high-speed network easily in their own places. Also the evolving of modern telecommunication technologies makes it possible for hand-held and mobile devices to access the Internet everywhere. However, these changes also bring several new problems. Since there are always bugs in softwares and most users are unaware of security flaws, Internet-connected personal computers or even enterprise servers are possible to be used to construct playgrounds for virus, worms, and hackers. The popularity of peer-to-peer file sharing and multimedia streaming softwares also brings new challenges to the network. The load of peer-to-peer traffic has now dominated the whole traffic and is even harmful to traditional Internet applications. In this thesis, we endeavored to solve problems brought by modern network applications in the matured networks, especially focused on network system security and heavy-loaded peer-to-peer traffic problems. Our methodologies to solve these problems can be explained briefly in three stages. First, we collect several different traces including publicly available Internet traces and privately header or full-payload packet traces in our campus. Based on these traces, we then design algorithms to detect, mitigate, and filter those unwanted or harmful network traffic. Finally, these algorithms are evaluated by running simulation using the collected real traffic. Our main contributions are three-fold. First, we propose a solution to detect and mitigate distributed denial-of-service between trusted network domains. The solution requires cooperations of the two trusted network domains. Therefore, we then propose another efficient algorithms to mitigate network attacks against general client networks, which is mostly composed of client hosts. The proposed algorithm, which is based on the observed traffic in our campus, does not need any cooperations and have only constant complexities on both computations and storage spaces. Although the algorithm is designed based on observations from campus network, we believe that the traffic we collected can be representative of general network because it is unfiltered. With a little bit of modifications, the algorithm can be also used to bound the upload peer-to-peer traffic in client networks. However, it has some probabilities of dropping non-attack or non-peer-to-peer traffic. For this reason, a more accurate co-algorithm is proposed to reduce the false positives induced by the main algorithm. With these solutions, we have successfully built network traffic filters to handle network attacks and upload peer-to-peer traffic.
Subjects
位元映像(位元陣列)
分散式服務阻斷 (DDoS) 攻擊
主機連線多樣性
同儕式計算
戳記
流量過濾
bitmap
distributed denial of service (DDoS) attack
host diversity
peer-to-peer computing
stamp
traffic filtering
Type
thesis

臺大位居世界頂尖大學之列,為永久珍藏及向國際展現本校豐碩的研究成果及學術能量,圖書館整合機構典藏(NTUR)與學術庫(AH)不同功能平台,成為臺大學術典藏NTU scholars。期能整合研究能量、促進交流合作、保存學術產出、推廣研究成果。

To permanently archive and promote researcher profiles and scholarly works, Library integrates the services of “NTU Repository” with “Academic Hub” to form NTU Scholars.

總館學科館員 (Main Library)
醫學圖書館學科館員 (Medical Library)
社會科學院辜振甫紀念圖書館學科館員 (Social Sciences Library)

開放取用是從使用者角度提升資訊取用性的社會運動,應用在學術研究上是透過將研究著作公開供使用者自由取閱,以促進學術傳播及因應期刊訂購費用逐年攀升。同時可加速研究發展、提升研究影響力,NTU Scholars即為本校的開放取用典藏(OA Archive)平台。(點選深入了解OA)

  • 請確認所上傳的全文是原創的內容,若該文件包含部分內容的版權非匯入者所有,或由第三方贊助與合作完成,請確認該版權所有者及第三方同意提供此授權。
    Please represent that the submission is your original work, and that you have the right to grant the rights to upload.
  • 若欲上傳已出版的全文電子檔,可使用Open policy finder網站查詢,以確認出版單位之版權政策。
    Please use Open policy finder to find a summary of permissions that are normally given as part of each publisher's copyright transfer agreement.
  • 網站簡介 (Quickstart Guide)
  • 使用手冊 (Instruction Manual)
  • 線上預約服務 (Booking Service)
  • 方案一:臺灣大學計算機中心帳號登入
    (With C&INC Email Account)
  • 方案二:ORCID帳號登入 (With ORCID)
  • 方案一:定期更新ORCID者,以ID匯入 (Search for identifier (ORCID))
  • 方案二:自行建檔 (Default mode Submission)
  • 方案三:學科館員協助匯入 (Email worklist to subject librarians)

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science