ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Journal Article Packet Aggregation and Abnormal Traffic Fitering Methodology for Network System Performance
Cited 0 time in scopus Share share facebook twitter linkedin kakaostory
Authors
Sang Wan KIM, Joon Kyung Lee, Dong won Kang, Sang Ha KIM
Issue Date
2012-04
Citation
International Journal of Information Processing and Management, v.3, no.2, pp.78-84
ISSN
2093-4009
Publisher
차세대융합기술연구원(AICIT)
Language
English
Type
Journal Article
DOI
https://dx.doi.org/10.4156/ijipm.vol3.issue2.9
Abstract
A normal traffic includes a plurality of packets in the same session, while most attack traffic consists of single packets generated in a single session. This papar relates to a method for aggregating single packets in a single session capable of detecting packets as attack traffic if the amount of single packets is excessively increased in a single session, and aggregating the single packets into a single flow to thus prevent degradation of a network's performance due to the attack traffic. If single packets in a single session are inputted, checking a single packet processing reference and selecting one among a packet processing threshold value (Las) for each autonomous system (AS), a packet processing threshold value (Lh) for each host, and an overall system packet processing threshold value (Ls); and if the amount of the single packets in a single session is larger than the selected packet processing threshold value, aggregating the single packets in the single session into a single flow. This paper provides a method and apparatus for aggregating single packets in a single session capable of detecting packets as attack traffic if the amount of single packets is excessively increased in a single session, and aggregating the single packets into a single flow to thus prevent degradation of a network's performance due to the attack traffic. Additionally we propose a methodology of abnormal traffic filtering based on the threshold values.