SVision: A novel visual network-anomaly identification technique

SVision: A novel visual network-anomaly identification technique
复制标题

SVision:一种新颖的视觉网络异常识别技术

DOI:
10.1016/j.cose.2006.10.001
复制
发表时间:
2007
影响因子:
5.6
通讯作者:
A. Ghorbani
A. Ghorbani
中科院分区:
计算机科学3区
文献类型:
--
作者:
Iosif;A. Ghorbani

文献摘要

被引文献

相似文献

我们提出了一种新的图形技术(SVision)的入侵检测,它的图片网络作为一个社区的主机独立漫游在一个3D空间定义的一组服务,他们使用。SVision的目的是以图形方式将主机分为正常和异常主机,只突出显示被认为对网络构成威胁的主机。我们的实验结果进行DARPA 1999年和2000年的入侵检测和评估数据集,以及真实的网络数据之间捕获的2003年和2005年从新玩法大学的主要链接,也是一个私人网络,显示所提出的技术作为一个很好的候选人,用于检测各种网络威胁,如垂直和水平扫描攻击,拒绝服务(DoS)攻击、分布式拒绝服务(DDoS)攻击以及蠕虫传播攻击。最后,可视化技术被证明可以科普网络中大量的主机,实验结果使用每个时间间隔多达1,000,000个不同IP的网络数据。
We propose a novel graphical technique (SVision) for intrusion detection, which pictures the network as a community of hosts independently roaming in a 3D space defined by the set of services that they use. The aim of SVision is to graphically cluster the hosts into normal and abnormal ones, highlighting only the ones that are considered as a threat to the network. Our experimental results conducted on DARPA 1999 and 2000 intrusion detection and evaluation datasets as well as real network data captured between 2003 and 2005 from the University of New Brunswick main link, and also a private network, show the proposed technique as a good candidate for the detection of various network threats such as vertical and horizontal scanning attacks, Denial of Service (DoS) attacks, Distributed DoS (DDoS) attacks, as well as worm propagation attack. Finally, the visualization technique proves to cope with high number of hosts in the network, the experimental results using network data of up to 1,000,000 distinct IPs per time interval.