How do we effectively monitor for slow suspicious activities

How do we effectively monitor for slow suspicious activities
复制标题

我们如何有效监控缓慢的可疑活动

DOI:
--
复制
发表时间:
2013
期刊:
Engineering Secure Software and Systems
影响因子:
--
通讯作者:
Anne E. James
Anne E. James
中科院分区:
--
文献类型:
--
作者:
Harsha K. Kalutarage;S. Shaikh;Qin Zhou;Anne E. James

文献摘要

参考文献

被引文献

相似文献

随着计算机网络规模的扩大和跟踪量的增加,检测到故意设置为低于阈值的缓慢可疑活动变得越来越难。由于计算限制,简单地存储所有数据包捕获以供分析是不可行的。检测此类活动依赖于在较长时间段内维护跟踪历史,并使用它来区分可疑节点和无辜节点。本文的博士工作旨在采用贝叶斯方法来解决这一问题,并检验这种方法在不同的网络条件下的有效性:多个攻击者、跟踪量、子网拥塞和跟踪采样。我们提供了我们的方法的理论描述和非常早期的实验结果。
As computer networks scale up in size and trac volume, detecting slow suspicious activity, deliberately designed to stay beneath the threshold, becomes ever more dicult. Simply storing all packet captures for analysis is not feasible due to computational constraints. Detecting such activity depends on maintaining trac history over extended periods of time, and using it to distinguish between suspicious and innocent nodes. The doctoral work presented here aims to adopt a Bayesian approach to address this problem, and to examine the eectiveness of such an approach under dierent network conditions: multiple attackers, trac volume, subnet conguration and trac sampling. We provide a theoretical account of our approach and very early experimental resuits.
知道要监视谁:识别其行为隐藏在误报和背景噪音中的攻击者
DOI: 10.1007/s10796-010-9268-7
发表时间: 2010
影响因子: 5.9
作者:
Chivers H
通讯作者: Chivers H