首页> 外文会议>International IFIP-TC6 Networking Conference(NETWORKING 2004); 20040509-20040514; Athens; GR >Detecting Traffic Anomalies through Aggregate Analysis of Packet Header Data
【24h】

Detecting Traffic Anomalies through Aggregate Analysis of Packet Header Data

机译:通过数据包头数据的聚合分析检测流量异常

获取原文
获取原文并翻译 | 示例

摘要

If efficient network analysis tools were available, it could become possible to detect the attacks, anomalies and to appropriately take action to contain the attacks. In this paper, we suggest a technique for traffic anomaly detection based on analyzing correlation of destination IP addresses in outgoing traffic at an egress router. This address correlation data are transformed through discrete wavelet transform for effective detection of anomalies through statistical analysis. Our techniques can be employed for postmortem and real-time analysis of outgoing network traffic at a campus edge. Results from trace-driven evaluation suggest that proposed approach could provide an effective means of detecting anomalies close to the network. We also present data analyzing the correlation of port numbers as a means of detecting anomalies.
机译:如果有有效的网络分析工具可用,则有可能检测到攻击,异常情况并采取适当措施来遏制攻击。在本文中,我们提出了一种在分析出口路由器上传出流量中目标IP地址相关性的基础上,进行流量异常检测的技术。该地址相关数据通过离散小波变换进行变换,以通过统计分析有效地检测异常。我们的技术可用于园区边缘的出站网络流量的事后分析和实时分析。跟踪驱动评估的结果表明,提出的方法可以提供一种检测网络附近异常的有效手段。我们还提出了分析端口号相关性的数据,作为检测异常的一种手段。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号