RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    Snort를 이용한 비정형 네트워크 공격패턴 탐지를 수행하는 Spark 기반 네트워크 로그 분석 시스템

    한글로보기

    https://www.riss.kr/link?id=A105303151

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
      • URL 복사
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    최근 네트워크 기술의 발달로 인해 다양한 분야에서 네트워크 기술이 사용되고 있다. 그러나 발전하는 네트워크 기술을 악용하여 공공기관, 기업 등을 대상으로 하는 공격 사례가 증가하였다. 한편 기존 네트워크 침입 탐지 시스템은 네트워크 로그의 양이 증가함에 따라 로그를 처리하는데 많은 시간이 소요된다. 따라서 본 논문에서는 Snort를 이용한 비정형 네트워크 공격패턴 탐지를 수행하는 Spark 기반의 네트워크 로그 분석 시스템을 제안한다. 제안하는 시스템은 대용량의 네트워크 로그 데이터에서 네트워크 공격 패턴탐지를 위해 필요한 요소를 추출하여 분석한다. 분석을 위해 Port Scanning, Host Scanning, DDoS, Worm 활동에 대해 네트워크 공격 패턴을 탐지하는 규칙을 제시하였으며, 이를 실제 로그 데이터에 적용하여 실제 공격 패턴 탐지를 잘 수행함을 보인다. 마지막으로 성능평가를 통해 제안하는 Spark 기반 로그 분석 시스템이 Hadoop 기반 시스템에 비해 로그 데이터 처리 성능이 2배 이상 우수함을 보인다.
    번역하기

    최근 네트워크 기술의 발달로 인해 다양한 분야에서 네트워크 기술이 사용되고 있다. 그러나 발전하는 네트워크 기술을 악용하여 공공기관, 기업 등을 대상으로 하는 공격 사례가 증가하였...

    최근 네트워크 기술의 발달로 인해 다양한 분야에서 네트워크 기술이 사용되고 있다. 그러나 발전하는 네트워크 기술을 악용하여 공공기관, 기업 등을 대상으로 하는 공격 사례가 증가하였다. 한편 기존 네트워크 침입 탐지 시스템은 네트워크 로그의 양이 증가함에 따라 로그를 처리하는데 많은 시간이 소요된다. 따라서 본 논문에서는 Snort를 이용한 비정형 네트워크 공격패턴 탐지를 수행하는 Spark 기반의 네트워크 로그 분석 시스템을 제안한다. 제안하는 시스템은 대용량의 네트워크 로그 데이터에서 네트워크 공격 패턴탐지를 위해 필요한 요소를 추출하여 분석한다. 분석을 위해 Port Scanning, Host Scanning, DDoS, Worm 활동에 대해 네트워크 공격 패턴을 탐지하는 규칙을 제시하였으며, 이를 실제 로그 데이터에 적용하여 실제 공격 패턴 탐지를 잘 수행함을 보인다. 마지막으로 성능평가를 통해 제안하는 Spark 기반 로그 분석 시스템이 Hadoop 기반 시스템에 비해 로그 데이터 처리 성능이 2배 이상 우수함을 보인다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Recently, network technology has been used in various fields due to development of network technology. However, there has been an increase in the number of attacks targeting public institutions and companies by exploiting the evolving network technology. Meanwhile, the existing network intrusion detection system takes much time to process logs as the amount of network log increases. Therefore, in this paper, we propose a Spark-based network log analysis system that detects unstructured network attack pattern. by using Snort. The proposed system extracts and analyzes the elements required for network attack pattern detection from large amount of network log data. For the analysis, we propose a rule to detect network attack patterns for Port Scanning, Host Scanning, DDoS, and worm activity, and can detect real attack pattern well by applying it to real log data. Finally, we show from our performance evaluation that the proposed Spark-based log analysis system is more than two times better on log data processing performance than the Hadoop-based system.
    번역하기

    Recently, network technology has been used in various fields due to development of network technology. However, there has been an increase in the number of attacks targeting public institutions and companies by exploiting the evolving network technolo...

    Recently, network technology has been used in various fields due to development of network technology. However, there has been an increase in the number of attacks targeting public institutions and companies by exploiting the evolving network technology. Meanwhile, the existing network intrusion detection system takes much time to process logs as the amount of network log increases. Therefore, in this paper, we propose a Spark-based network log analysis system that detects unstructured network attack pattern. by using Snort. The proposed system extracts and analyzes the elements required for network attack pattern detection from large amount of network log data. For the analysis, we propose a rule to detect network attack patterns for Port Scanning, Host Scanning, DDoS, and worm activity, and can detect real attack pattern well by applying it to real log data. Finally, we show from our performance evaluation that the proposed Spark-based log analysis system is more than two times better on log data processing performance than the Hadoop-based system.

    더보기

    목차 (Table of Contents)

    • 요약
    • Abstract
    • Ⅰ. 서론
    • Ⅱ. 연구 배경 및 관련 연구
    • Ⅲ. Spark 기반 네트워크 로그 분석 시스템
    • 요약
    • Abstract
    • Ⅰ. 서론
    • Ⅱ. 연구 배경 및 관련 연구
    • Ⅲ. Spark 기반 네트워크 로그 분석 시스템
    • Ⅳ. 네트워크 공격패턴 분석 및 시각화
    • Ⅴ. 성능평가
    • Ⅵ. 결론
    • 참고문헌
    더보기

    참고문헌 (Reference)

    1 "https://www.snort.org/"

    2 "https://www.r-project.org/"

    3 "https://www.bro.org/"

    4 "https://oisf.net/suricata/"

    5 "https://hadoop.apache.org/"

    6 "http://www.vacommunity.org/VASTChallenge 2012"

    7 "http://www.hping.org/"

    8 "http://spark.apache.org/"

    9 Cook, Kristin, "VAST Challenge 2012:Visual analytics for big data" IEEE 2012

    10 Matei Zaharia, "Spark: Cluster computing with working sets" 10 (10): 95-, 2010

    1 "https://www.snort.org/"

    2 "https://www.r-project.org/"

    3 "https://www.bro.org/"

    4 "https://oisf.net/suricata/"

    5 "https://hadoop.apache.org/"

    6 "http://www.vacommunity.org/VASTChallenge 2012"

    7 "http://www.hping.org/"

    8 "http://spark.apache.org/"

    9 Cook, Kristin, "VAST Challenge 2012:Visual analytics for big data" IEEE 2012

    10 Matei Zaharia, "Spark: Cluster computing with working sets" 10 (10): 95-, 2010

    11 Matei Zaharia, "Resilient distributed datasets: A fault-tolerant abstractVion for in-memory cluster computing" USENIX 2012

    12 이동건, "RGB Palette를 이용한 보안 로그 시각화 및보안 위협 인식" 한국정보보호학회 25 (25): 61-73, 2015

    13 최대수, "MapReduce를 이용한 대용량 보안 로그 분석" 한국정보기술학회 9 (9): 125-132, 2011

    14 장진수, "MapReduce 환경에서네트워크 공격 탐지를 위한 실시간 로그 분석 시스템 개발" 2017

    15 Khamphakdee, "Improving intrusion detection system based on snort rules for network probe attack detection" IEEE 2014

    16 J. J. Cheon, "Distributed processing of snort alert log using hadoop" 5 (5): 2685-2690, 2013

    17 P. G. Prathibha, "Design of a hybrid intrusion detection system using snort and hadoop" 73 (73): 2013

    18 Anna Sperotto, "An overview of ip flow-based intrusion detection" 12 (12): 343-356, 2010

    19 Jian Zhang, "A Hadoop Based Analysis and Detection Model for IP Spoofing Typed DDoS Attack" Trustcom, BigDataSE, ISPA, 2016IEEE. IEEE 2016

    더보기

    동일학술지(권/호) 다른 논문

    동일학술지 더보기

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    인용정보 인용지수 설명보기

    학술지 이력

    학술지 이력
    연월일 이력구분 이력상세 등재구분
    2027 평가 재인증평가 신청대상 (재인증)
    2021-01-01 등재 등재학술지 유지 (재인증) KCI등재
    2018-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2015-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2011-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2008-01-01 등재 등재학술지 선정 (등재후보2차) KCI등재
    2007-05-04 학회명변경 영문명 : The Korea Contents Society -> The Korea Contents Association KCI등재후보
    2007-01-01 등재 등재후보 1차 PASS (등재후보1차) KCI등재후보
    2006-01-01 등재 등재후보학술지 유지 (등재후보1차) KCI등재후보
    2004-01-01 등재 등재후보학술지 선정 (신규평가) KCI등재후보
    더보기

    학술지 인용정보

    학술지 인용정보
    기준연도 WOS-KCI 통합IF(2년) KCIF(2년) KCIF(3년)
    2016 1.21 1.21 1.26
    KCIF(4년) KCIF(5년) 중심성지수(3년) 즉시성지수
    1.29 1.25 1.573 0.33
    더보기

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼