Visualisation for Intrusion Detection Hooking the Worm
Visualisation for Intrusion Detection Hooking the Worm
复制标题
可视化入侵检测钩住蠕虫
DOI:
--
复制
发表时间:
2003
期刊:
影响因子:
--
通讯作者:
Stefan Axelsson
中科院分区:
文献类型:
--
作者:
Stefan Axelsson
Even though intrusion detection systems have been studied for a number of years several problems remain; chiefly low detection rates and high false alarm rates. Instead of building automated alarms that trigger when a computer security violation takes place, we propose to visualise the state of the computer system such that the operator himself can determine whether a violation has taken place. In effect replacing the “burglar alarm” with a “security camera”. In order to illustrate the use of visualisation for intrusion detection purposes, we applied a trellis plot of parallel coordinate visualisations to the log of a small personal web server. The intent was to find patterns of malicious activity from so called worms, and to be able to distinguish between them and benign traffic. Several such patterns were found, including one that was unknown at the time to the security community at large.