Please use this identifier to cite or link to this item: https://repository.cihe.edu.hk/jspui/handle/cihe/1944
DC FieldValueLanguage
dc.contributor.authorChiu, Dah Mingen_US
dc.contributor.otherHu, Y.-
dc.contributor.otherLui, J. C. S.-
dc.date.accessioned2021-11-25T12:10:19Z-
dc.date.available2021-11-25T12:10:19Z-
dc.date.issued2009-
dc.identifier.urihttps://repository.cihe.edu.hk/jspui/handle/cihe/1944-
dc.description.abstractInternet traffic flow measurement is vitally important for network management, accounting and performance studies. Cisco's NetFlow is a widely deployed flow measurement solution that uses a configurable static sampling rate to control processor and memory usage on the router and the amount of reporting flow records generated. But during flooding attacks the memory and network bandwidth consumed by flow records can increase beyond what is available. Currently available countermeasures have their own problems: 1) reject new flows when the cache is full - some legitimate new flows will not be counted; 2) export not-terminated flows to make room for new ones - this will exhaust the export bandwidth; and 3) adapt the sampling rate to traffic rate - this will reduce the overall accuracy of accounting, including legitimate flows. In this paper, we propose an entropy based adaptive flow aggregation algorithm. Relying on information-theoretic techniques, the algorithm efficiently identifies the clusters of attack flows in real time and aggregates those large number of short attack flows into a few metaflows. Compared to currently available solutions, our solution not only alleviates the problem in memory and export bandwidth, but also significantly improves the accuracy of legitimate flows. Finally, we evaluate our system using both synthetic trace file and real trace files from the Internet.en_US
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.relation.ispartofIEEE/ACM Transactions on Networkingen_US
dc.titleEntropy based adaptive flow aggregationen_US
dc.typejournal articleen_US
dc.identifier.doi10.1109/TNET.2008.2002560-
dc.contributor.affiliationFelizberta Lo Padilla Tong School of Social Sciencesen_US
dc.relation.issn1558-2566en_US
dc.description.volume17en_US
dc.description.issue3en_US
dc.description.startpage698en_US
dc.description.endpage711en_US
dc.cihe.affiliatedNo-
item.fulltextNo Fulltext-
item.grantfulltextnone-
item.openairecristypehttp://purl.org/coar/resource_type/c_6501-
item.cerifentitytypePublications-
item.openairetypejournal article-
item.languageiso639-1en-
crisitem.author.deptFelizberta Lo Padilla Tong School of Social Sciences-
crisitem.author.orcid0000-0003-0566-5223-
Appears in Collections:SS Publication
SFX Query Show simple item record

Google ScholarTM

Check

Altmetric

Altmetric


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.