ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Conference Paper Traffic Storing and Related Information Generation System for Cyber Attack Analysis
Cited 1 time in scopus Share share facebook twitter linkedin kakaostory
Authors
Yangseo Choi, Joo-Young Lee, Sunoh Choi, Jong-Hyun Kim, Ikkyun Kim
Issue Date
2016-10
Citation
International Conference on Information and Communication Technology Convergence (ICTC) 2016, pp.1052-1057
Publisher
IEEE
Language
English
Type
Conference Paper
DOI
https://dx.doi.org/10.1109/ICTC.2016.7763366
Abstract
As the sophisticated attacks are increased continuously, the attack analysis technologies are getting more important. It is needed to collect attack related information or data first for the attack analysis. But attackers make an effort to get rid of all the attack related information that they can find and adopt anti-forensic technologies as well, so it is quite difficult to collect sufficient information for attack analysis. For further analysis network traffic could be a good candidate. It could not be removed by the attackers and has a lot of information about what the attackers were doing. However, network traffic is volatile information and only exist while they are being transmitted. Therefore, in order to collect network packets they have to be stored while they are being transmitted in real time. Besides, network traffic is huge amount of volatile data so it should be captured and stored on a mass storage device. For that we propose a Traffic storing and Related Information Generation system for cyberattack analysis, TRIG, which can store 20Gbps network traffic in real time and generate various traffic related information at the same time for further analysis.
KSP Keywords
Attack analysis, Cyber attacks, Generation system, Mass storage, Real-time, Sophisticated attacks, Storage device, anti-forensic, network packets, network traffic, traffic storing