| B. Tjaden, L. Welch, S. Ostermann, D. Chelberg, R. Balupari, M. Bykova, M. Delaney, A. Mitchell, S. Li, D. Lissitsyn, and L. Tong, "INBOUNDS: The Integrated NetworkBased Ohio University Network Detective Service", 4th World Multiconference on Systemics, Cybernetics, and Informatics (SCI'2000), Jul. 2000. |
....and not at their contents. Our approach allows us to recognize not only known attacks but also to detect suspicious activity that may be the result of a new, unknown attack. This paper describes certain aspects of the Integrated Network Based Ohio University Network Detective Service (INBOUNDS) [19], an IDS under development at Ohio University. Section II provides a description of the monitored link, tools used, the types and amount of data analyzed, and the analysis performed. Section III covers the results obtained from our experiments. All detected errors are divided into categories and ....
....connection between Ohio University and its ISP and carry packets for approximately 20,000 local hosts. B. Tools used We used tcpdump [9] to capture data from Ohio University s main Internet link and tcptrace [11] to analyze it. A special tcptrace module designed for the INBOUNDS project [19] was used to send data to other modules of the IDS and report abnormal behavior. C. Packet Analysis Analysis of the monitored link shows that almost all packets on the link are IP packets and the great majority of those are TCP packets. UDP traffic comprises approximately 2 percent of the ....
B. Tjaden, L. Welch, S. Ostermann, D. Chelberg, R. Balupari, M. Bykova, M. Delaney, A. Mitchell, S. Li, D. Lissitsyn, and L. Tong, "INBOUNDS: The Integrated NetworkBased Ohio University Network Detective Service", 4th World Multiconference on Systemics, Cybernetics, and Informatics (SCI'2000), Jul. 2000.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC