A Statistical Analysis of Attack Data to Separate Attacks

A Statistical Analysis of Attack Data to Separate Attacks
复制标题

攻击数据统计分析,区分攻击

DOI:
--
复制
发表时间:
2006
期刊:
Dependable Systems and Networks
影响因子:
--
通讯作者:
Stephanie Tan
Stephanie Tan
中科院分区:
--
文献类型:
--
作者:
M. Cukier;R. Berthier;S. Panjwani;Stephanie Tan

文献摘要

被引文献

相似文献

本文分析了从一个测试平台收集的恶意活动,该测试平台由两台专门用于攻击目的的目标计算机组成,为期109天。我们从恶意活动中分离了端口扫描、恶意软件扫描和漏洞扫描。在其余的攻击数据中,超过78%(即,3,677次攻击)针对端口445,然后对其进行统计分析。目标是找到最有效地分离攻击的特征。首先,我们通过分析它们的消息来分离攻击。然后利用K-Means算法对攻击进行聚类特征分离。对报文的分析结果与K-Means算法的结果进行了比较,结果表明:1)报文、字节和报文长度随时间的分布均值是区分攻击的较差特征; 2)字节数、字节分布均值和报文长度作为报文数的函数是区分攻击的最佳特征
This paper analyzes malicious activity collected from a test-bed, consisting of two target computers dedicated solely to the purpose of being attacked, over a 109 day time period. We separated port scans, ICMP scans, and vulnerability scans from the malicious activity. In the remaining attack data, over 78% (i.e., 3,677 attacks) targeted port 445, which was then statistically analyzed. The goal was to find the characteristics that most efficiently separate the attacks. First, we separated the attacks by analyzing their messages. Then we separated the attacks by clustering characteristics using the K-Means algorithm. The comparison between the analysis of the messages and the outcome of the K-Means algorithm showed that 1) the mean of the distributions of packets, bytes and message lengths over time are poor characteristics to separate attacks and 2) the number of bytes, the mean of the distribution of bytes and message lengths as a function of the number packets are the best characteristics for separating attacks