Honeycomb

Honeycomb
复制标题

DOI:
10.1145/972374.972384
复制
发表时间:
2004-01
影响因子:
2.8
通讯作者:
C. Kreibich;J. Crowcroft
C. Kreibich;J. Crowcroft
中科院分区:
计算机科学4区
文献类型:
--
作者:
C. Kreibich;J. Crowcroft

文献摘要

被引文献

相似文献

本文描述了一个用于网络入侵检测系统的攻击特征自动生成系统。我们的系统应用模式匹配技术和协议一致性检查的多个层次上的协议层次结构的网络流量捕获的蜜罐系统。我们目前的结果运行系统在一个不受保护的电缆调制解调器连接24小时。该系统成功地创建了精确的交通签名,否则需要安全官员的技能和时间来手动检查交通。
This paper describes a system for automated generation of attack signatures for network intrusion detection systems. Our system applies pattern-matching techniques and protocol conformance checks on multiple levels in the protocol hierarchy to network traffic captured a honeypot system. We present results of running the system on an unprotected cable modem connection for 24 hours. The system successfully created precise traffic signatures that otherwise would have required the skills and time of a security officer to inspect the traffic manually.