Paper Abstract and Keywords |
Presentation |
2012-03-09 09:30
Discriminating malcious packets using TTL in the IP header Ryo Yamada, Kazuhiro Tobe, Shigeki Goto (Waseda University) IN2011-176 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
It is known that an IP packet passes through less than 30 routers before it reaches the destination host. According to our observation, there are strange IP packets whose Time-To-Live (TTL) values are decreased more than 30 from the initial TTL. These packets are likely to be generated by a special software. We assume that IP packets with strange TTLs are malicious. This paper investigate this conjecture through several experiments. As a result, we show that it is possible to discriminate malicious packets from legitimate ones only by observing TTL values. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
TTL / hop count / malicious traffic / network security / / / / |
Reference Info. |
IEICE Tech. Rep., vol. 111, no. 469, IN2011-176, pp. 235-240, March 2012. |
Paper # |
IN2011-176 |
Date of Issue |
2012-03-01 (IN) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
IN2011-176 |
Conference Information |
Committee |
NS IN |
Conference Date |
2012-03-08 - 2012-03-09 |
Place (in Japanese) |
(See Japanese page) |
Place (in English) |
Miyazaki Seagia |
Topics (in Japanese) |
(See Japanese page) |
Topics (in English) |
General |
Paper Information |
Registration To |
IN |
Conference Code |
2012-03-NS-IN |
Language |
Japanese |
Title (in Japanese) |
(See Japanese page) |
Sub Title (in Japanese) |
(See Japanese page) |
Title (in English) |
Discriminating malcious packets using TTL in the IP header |
Sub Title (in English) |
|
Keyword(1) |
TTL |
Keyword(2) |
hop count |
Keyword(3) |
malicious traffic |
Keyword(4) |
network security |
Keyword(5) |
|
Keyword(6) |
|
Keyword(7) |
|
Keyword(8) |
|
1st Author's Name |
Ryo Yamada |
1st Author's Affiliation |
Waseda University (Waseda University) |
2nd Author's Name |
Kazuhiro Tobe |
2nd Author's Affiliation |
Waseda University (Waseda University) |
3rd Author's Name |
Shigeki Goto |
3rd Author's Affiliation |
Waseda University (Waseda University) |
4th Author's Name |
|
4th Author's Affiliation |
() |
5th Author's Name |
|
5th Author's Affiliation |
() |
6th Author's Name |
|
6th Author's Affiliation |
() |
7th Author's Name |
|
7th Author's Affiliation |
() |
8th Author's Name |
|
8th Author's Affiliation |
() |
9th Author's Name |
|
9th Author's Affiliation |
() |
10th Author's Name |
|
10th Author's Affiliation |
() |
11th Author's Name |
|
11th Author's Affiliation |
() |
12th Author's Name |
|
12th Author's Affiliation |
() |
13th Author's Name |
|
13th Author's Affiliation |
() |
14th Author's Name |
|
14th Author's Affiliation |
() |
15th Author's Name |
|
15th Author's Affiliation |
() |
16th Author's Name |
|
16th Author's Affiliation |
() |
17th Author's Name |
|
17th Author's Affiliation |
() |
18th Author's Name |
|
18th Author's Affiliation |
() |
19th Author's Name |
|
19th Author's Affiliation |
() |
20th Author's Name |
|
20th Author's Affiliation |
() |
Speaker |
Author-1 |
Date Time |
2012-03-09 09:30:00 |
Presentation Time |
20 minutes |
Registration for |
IN |
Paper # |
IN2011-176 |
Volume (vol) |
vol.111 |
Number (no) |
no.469 |
Page |
pp.235-240 |
#Pages |
6 |
Date of Issue |
2012-03-01 (IN) |
|