Visualisation for Intrusion Detection Hooking the Worm

Visualisation for Intrusion Detection Hooking the Worm
复制标题

可视化入侵检测钩住蠕虫

DOI:
--
复制
发表时间:
2003
期刊:
影响因子:
--
通讯作者:
Stefan Axelsson
Stefan Axelsson
中科院分区:
--
文献类型:
--
作者:
Stefan Axelsson

文献摘要

被引文献

相似文献

尽管入侵检测系统已经研究多年,但仍然存在一些问题;主要是检测率低、误报率高。我们建议将计算机系统的状态可视化,以便操作员自己可以确定是否发生了违规行为,而不是构建在发生计算机安全违规时触发的自动警报。实际上用“安全摄像头”取代了“防盗警报器”。为了说明可视化在入侵检测中的用途,我们将并行坐标可视化的网格图应用于小型个人 Web 服务器的日志。目的是找到所谓蠕虫病毒的恶意活动模式,并能够区分它们和良性流量。我们发现了几种这样的模式,其中包括当时整个安全界都不知道的一种模式。
Even though intrusion detection systems have been studied for a number of years several problems remain; chiefly low detection rates and high false alarm rates. Instead of building automated alarms that trigger when a computer security violation takes place, we propose to visualise the state of the computer system such that the operator himself can determine whether a violation has taken place. In effect replacing the “burglar alarm” with a “security camera”. In order to illustrate the use of visualisation for intrusion detection purposes, we applied a trellis plot of parallel coordinate visualisations to the log of a small personal web server. The intent was to find patterns of malicious activity from so called worms, and to be able to distinguish between them and benign traffic. Several such patterns were found, including one that was unknown at the time to the security community at large.