Design and Implementation of an Active Network Behavior Detection Method
HE Zhongkun
Abstract
HE Zhongkun
Abstract
The simplicity and open character of TCP/IP has brought great success to internet. However, it also arouses problems on network security and management. The control of current network communication behavior becomes a basic task of network management. Detection on network behavior not only helps one understand current application status of campus network, but also detects hidden troubles on network security and management. This paper puts forward an active detection method on current network communication behavior. By this method, network communication logs can be automatically drawn from related gateways based on previously set detection requirement. The network communication behavior of targeted object can be achieved by analyzing these logs. Experiments under campus network environment show that by using this method, we can not only get the current communication behavior of campus network, but also find doubted proxy servers and computers that may contain sasser worm virus.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The simplicity and open character of TCP/IP has brought great success to internet. However, it also arouses problems on network security and management. The control of current network communication behavior becomes a basic task of network management. Detection on network behavior not only helps one understand current application status of campus network, but also detects hidden troubles on network security and management. This paper puts forward an active detection method on current network communication behavior. By this method, network communication logs can be automatically drawn from related gateways based on previously set detection requirement. The network communication behavior of targeted object can be achieved by analyzing these logs. Experiments under campus network environment show that by using this method, we can not only get the current communication behavior of campus network, but also find doubted proxy servers and computers that may contain sasser worm virus.
Key concepts: Computer science, Network management station, Network management, Network security, Computer network, Campus network, Network monitoring, Computer security