How do we effectively monitor for slow suspicious activities
How do we effectively monitor for slow suspicious activities
复制标题
我们如何有效监控缓慢的可疑活动
DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
Anne E. James
中科院分区:
文献类型:
--
作者:
Harsha K. Kalutarage;S. Shaikh;Qin Zhou;Anne E. James
As computer networks scale up in size and trac volume, detecting slow suspicious activity, deliberately designed to stay beneath the threshold, becomes ever more dicult. Simply storing all packet captures for analysis is not feasible due to computational constraints. Detecting such activity depends on maintaining trac history over extended periods of time, and using it to distinguish between suspicious and innocent nodes. The doctoral work presented here aims to adopt a Bayesian approach to address this problem, and to examine the eectiveness of such an approach under dierent network conditions: multiple attackers, trac volume, subnet conguration and trac sampling. We provide a theoretical account of our approach and very early experimental resuits.
影响因子:
5.9
作者:
Chivers H
通讯作者:
Chivers H