A Framework of Network Attacker-Tracing System

谷大武,李小勇,陆海宁
DOI: https://doi.org/10.3321/j.issn:1006-2467.2003.03.028
2003-01-01
Shanghai Jiaotong Daxue Xuebao/Journal of Shanghai Jiaotong University
Abstract:Intrusion detection is a major technique of identifying the network attackers. The intrusion detection systems available can find the event of most network-based attacks, but cannot judge the real locations of attackers. On the basis of the existing techniques, this paper presented a framework of network attacker-tracing system. It then provided the system architecture and listed the principal functions. By using of the relevant analysis, it gave the basic idea of retracing the attackers' paths. The simulation result shows that the framework and idea are feasible and efficient. Finally, the potential problems of such system from various respects such as security, practicability and tracing precision, etc. were analyzed.
What problem does this paper attempt to address?