首页> 外文会议>24th international conference on computers and their applications 2009 >An Information Theoretic Model for Protocol Graph Based Anomaly Analysis
【24h】

An Information Theoretic Model for Protocol Graph Based Anomaly Analysis

机译:基于协议图异常分析的信息理论模型

获取原文
获取原文并翻译 | 示例

摘要

One of the major problems in network behavior analysis is to discover the underlying patterns from huge amount of network traffic data in order to identify anomalies from the norm. A great deal of work has been conducted through modeling the attribute-value network traffic data into different models. However, the abstract models generated by machine learning or data mining techniques prevent users from understanding the network behaviors very well. Network protocols, e.g., TCP, UDP, define the format of messages and legitimate sequence of the messages. To explicitly bridge the semantic gap between the abstract models and the human recognizable knowledge, we propose a new information theoretic model that utilizes protocol structural information and statistical techniques to analyze the network behaviors. We define new metrics and propose methods to identify unexpected anomalies, incomplete anomalies, and dominant anomalies within the information theoretic model framework. The method is evaluated using real-world network data.
机译:网络行为分析的主要问题之一是从大量的网络流量数据中发现潜在的模式,以便从规范中识别异常。通过将属性值网络流量数据建模为不同的模型,已经进行了大量工作。但是,由机器学习或数据挖掘技术生成的抽象模型使用户无法很好地理解网络行为。网络协议,例如TCP,UDP,定义了消息的格式和消息的合法顺序。为了明确弥补抽象模型和人类可识别知识之间的语义鸿沟,我们提出了一种新的信息理论模型,该模型利用协议结构信息和统计技术来分析网络行为。我们定义了新的指标并提出了在信息理论模型框架内识别意外异常,不完整异常和显性异常的方法。使用实际的网络数据评估该方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号