Detekce anomálií v ICMP provozu
Miroslav Piter
Abstract
Miroslav Piter
Abstract
The point of this bachelor thesis is to describe the anomalies and ICMP exploits, and to propose the actions for detecting them and verify these actions in practice. The theoretical part of this thesis describes the basic protocols and their position in the reference model TCP/IP and ISO OSI, their headers and properties. It mentions briefly the principle of filtering NetFlow data using nfdump. The practical part describes chosen anomalies and ICMP exploits and by which means they occur. Further I focus on their impact on the network traffic and their detection possibilities using NetFlow technology. The results of this thesis are nfdump filters to detect these anomalies.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The point of this bachelor thesis is to describe the anomalies and ICMP exploits, and to propose the actions for detecting them and verify these actions in practice. The theoretical part of this thesis describes the basic protocols and their position in the reference model TCP/IP and ISO OSI, their headers and properties. It mentions briefly the principle of filtering NetFlow data using nfdump. The practical part describes chosen anomalies and ICMP exploits and by which means they occur. Further I focus on their impact on the network traffic and their detection possibilities using NetFlow technology. The results of this thesis are nfdump filters to detect these anomalies.
Key concepts: Internet Control Message Protocol, NetFlow, Computer science, Exploit, Focus (optics), traceroute, Data mining, Computer network