Science Forums
| View previous topic :: View next topic |
| Author |
Message |
simon Guest
|
Posted: Thu Jun 19, 2008 5:03 pm Post subject: Measured Features for Detecting Attacks |
|
|
Hi, I find that many network attacks can be detected by measuring one
single feature. For example, the SYN Flood can be detected by counting
the number of SYN packets sent to a destination address. The measured
feature is the number of SYN packets.
Is there an attack that should be detected by at least two features?
Can anyone give me an example and the relevant features?
Thanks a lot!
Simon |
|
| Back to top |
|
 |
| |
Ads |
Advertising
Sponsor
|
|
Ertugrul Söylemez Guest
|
Posted: Fri Jun 20, 2008 11:01 am Post subject: Re: Measured Features for Detecting Attacks |
|
|
simon <Simon.SCh.000@gmail.com> wrote:
| Quote: |
Hi, I find that many network attacks can be detected by measuring one
single feature. For example, the SYN Flood can be detected by counting
the number of SYN packets sent to a destination address. The measured
feature is the number of SYN packets.
Is there an attack that should be detected by at least two features?
Can anyone give me an example and the relevant features?
|
You should be more accurate as to what a "feature" is, but I can give
you two examples of attacks, which require measuring as many features as
possible.
1. Man in the middle (MITM) attack: A perfect MITM attack against a
non-authenticated cryptosystem is impossible to detect. All features
you measure only give evidences.
2. Side channel attack: In an ideal case for the attacker, a side
channel attack is impossible to detect. All features you measure only
give evidences.
Greets,
Ertugrul.
--
http://ertes.de/ |
|
| Back to top |
|
 |
| |
Ads |
Advertising
Sponsor
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|

102 Attacks blocked
Powered by phpBB © 2001, 2005 phpBB Group
|