首页> 外文会议>International conference on similarity search and applications >Malware Discovery Using Behaviour-Based Exploration of Network Traffic
【24h】

Malware Discovery Using Behaviour-Based Exploration of Network Traffic

机译:使用基于行为的网络流量探索恶意软件发现

获取原文

摘要

We present a demo of behaviour-based similarity retrieval in network traffic data. The underlying framework is intended to support domain experts searching for network nodes (computers) infected by malicious software, especially in cases when single client-server communication does not have to be sufficient to reliably identify the infection. The focus is on interactive browsing enabling dynamic changes of the retrieval model, which is based on a recently proposed statistical description (fingerprint) of a communication between two network hosts and the bag of features approach. The demo/framework provides unique insight into the data and enables annotation of the data and model modifications during the search for more effective identification of infected hosts.
机译:我们在网络流量数据中展示了基于行为的相似性检索的演示。基础框架旨在支持寻找由恶意软件感染的网络节点(计算机)的域专家,特别是在单个客户端 - 服务器通信不必足以可靠地识别感染时的情况下。重点是在交互式浏览中,实现检索模型的动态变化,这是基于两个网络主机之间的通信的最近提出的统计描述(指纹)和特征方法。演示/框架为数据提供了独特的洞察力,并在搜索期间批准数据和模型修改,以更有效地识别受感染的主机。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号