完整後設資料紀錄
DC 欄位語言
dc.contributor.authorChen, CSen_US
dc.contributor.authorTseng, SSen_US
dc.contributor.authorLiu, CLen_US
dc.date.accessioned2014-12-08T15:41:49Z-
dc.date.available2014-12-08T15:41:49Z-
dc.date.issued2002-11-01en_US
dc.identifier.issn1016-2364en_US
dc.identifier.urihttp://hdl.handle.net/11536/28437-
dc.description.abstractWe have investigated the problem of detecting DoS-like DNS anomalies in DNS system. In this paper, we propose a distributed Two-phase DNS anomaly detection model for solving the problem. Three sets of algorithms corresponding to different configurations are proposed, including one sequential algorithm and two distributed algorithms, each with an increasing level of parallelism. The complexity of these algorithms have been found to be O (n l(og)n). The distributed algorithms show at least a constant (1-1/C-k), C-k > 1, improvement over the sequential one. To evaluate the performance, we have implemented the algorithms and applied them to a number of examples. The experimental result shows a speed up of about 1.68 on the test example for running on an enhanced distributed architecture with C-IDS over the sequential one. A higher speedup might be common because DNS anomalies will make the traffic distribution more concentrated on the outliers, and the computation will usually converge much more quickly.en_US
dc.language.isoen_USen_US
dc.subjectDoSen_US
dc.subjectDNSen_US
dc.subjectdistributed two-phase DNS anomaly detectionen_US
dc.subjectIDSen_US
dc.subjecttwo-phase anomaly detection algorithmsen_US
dc.titleA distributed intrusion detection model for the domain name systemen_US
dc.typeArticleen_US
dc.identifier.journalJOURNAL OF INFORMATION SCIENCE AND ENGINEERINGen_US
dc.citation.volume18en_US
dc.citation.issue6en_US
dc.citation.spage999en_US
dc.citation.epage1009en_US
dc.contributor.department資訊工程學系zh_TW
dc.contributor.departmentDepartment of Computer Scienceen_US
dc.identifier.wosnumberWOS:000179148700008-
dc.citation.woscount1-
顯示於類別:期刊論文