Kalman Filter Based DNS Cache Poisoning Attack Detection

被引:0
|
作者
Wu, Hao [1 ]
Dang, Xianglei [1 ]
Zhang, Liang [1 ]
Wang, Lidong [1 ]
机构
[1] CNCERT CC, Beijing, Peoples R China
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Detection for Domain Name Systems cache poisoning attack is investigated. We exploit the fact that when attack is happening, the entropies of the query packet IP addresses of the cache server will have a decrease, to detect the cache poisoning attack. We pay attention to the detection method for the case that the entropy sequence has nonstationary dynamic at normal cases. In order to handle the nonstationarity, we first model the entropy sequence by a state space equation, and then we utilize Kalman filter to implement the attack detection. The problem is discussed for single and distributed cache poisoning attack, respectively. For the single one, we use the measurement errors to detect the anomaly. Under distributed attack, we utilize the correlation variation of the prediction errors to detect the attack event and identify the attacked cache servers. An experiment is illustrated to verify the effectiveness of our presented method.
引用
收藏
页码:1594 / 1600
页数:7
相关论文
共 50 条
  • [41] A STATISTICAL EDGE DETECTION ALGORITHM BASED ON KALMAN FILTER
    You, Lihua
    Wu, Jingjing
    Cao, Yi
    JOURNAL OF INVESTIGATIVE MEDICINE, 2014, 62 (08) : S27 - S28
  • [42] A Kalman Filter Based Method for GPS Spoofing Detection
    Chen, Hao
    Fan, H. Howard
    PROCEEDINGS OF THE 2016 INTERNATIONAL TECHNICAL MEETING OF THE INSTITUTE OF NAVIGATION, 2016, : 151 - 159
  • [43] Detection of violations based on sensitivity equations of a Kalman filter
    I. V. Semushin
    A. G. Skovikov
    L. V. Kalinin
    Measurement Techniques, 1997, 40 : 839 - 843
  • [44] Detection of Violations Based on Sensitivity Equations of a Kalman Filter
    Semushin, I. V.
    Skovikov, A. G.
    Kalinin, L. V.
    Measurement Techniques (English translation of Izmeritel'naya Tekhnika), 40 (09):
  • [45] Detection of violations based on sensitivity equations of a Kalman filter
    Semushin, IV
    Skovikov, AG
    Kalinin, LV
    MEASUREMENT TECHNIQUES, 1997, 40 (09) : 839 - 843
  • [46] Detection and isolation of false data injection attack via adaptive Kalman filter bank
    Luo, Xiaoyuan
    Zhu, Minggao
    Wang, Xinyu
    Guan, Xinping
    JOURNAL OF CONTROL AND DECISION, 2024, 11 (01) : 60 - 72
  • [47] On change detection in a Kalman filter based tracking problem
    Moussakhani, B.
    Flam, J. T.
    Ramstad, T. A.
    Balasingham, I.
    SIGNAL PROCESSING, 2014, 105 : 268 - 276
  • [48] Blind detection of CDMA signals based on Kalman filter
    Xu, ZY
    Wang, T
    CONFERENCE RECORD OF THE THIRTY-FIFTH ASILOMAR CONFERENCE ON SIGNALS, SYSTEMS AND COMPUTERS, VOLS 1 AND 2, 2001, : 1545 - 1549
  • [49] Command current detection algorithm based on Kalman filter
    Li, Falei
    Cheng, Xingong
    Zong, Xiju
    Li, Lisheng
    PROCEEDINGS OF 2018 IEEE 4TH INFORMATION TECHNOLOGY AND MECHATRONICS ENGINEERING CONFERENCE (ITOEC 2018), 2018, : 1048 - 1053
  • [50] Lane detection algorithm based on extended Kalman filter
    Peng, Hong
    Xiao, Jin-Sheng
    Cheng, Xian
    Li, Bi-Jun
    Song, Xiao
    Guangdianzi Jiguang/Journal of Optoelectronics Laser, 2015, 26 (03): : 567 - 574