首页> 外文会议>International conference on similarity search and applications >Malware Discovery Using Behaviour-Based Exploration of Network Traffic
【24h】

Malware Discovery Using Behaviour-Based Exploration of Network Traffic

机译:使用基于行为的网络流量探索进行恶意软件发现

获取原文
获取外文期刊封面目录资料

摘要

We present a demo of behaviour-based similarity retrieval in network traffic data. The underlying framework is intended to support domain experts searching for network nodes (computers) infected by malicious software, especially in cases when single client-server communication does not have to be sufficient to reliably identify the infection. The focus is on interactive browsing enabling dynamic changes of the retrieval model, which is based on a recently proposed statistical description (fingerprint) of a communication between two network hosts and the bag of features approach. The demo/framework provides unique insight into the data and enables annotation of the data and model modifications during the search for more effective identification of infected hosts.
机译:我们展示了网络流量数据中基于行为的相似性检索的演示。该基础框架旨在支持域专家搜索受恶意软件感染的网络节点(计算机),尤其是在单个客户端与服务器之间的通信不一定足以可靠地识别感染的情况下。重点在于交互式浏览,该交互式浏览可实现检索模型的动态更改,该交互式浏览基于最近提出的两个网络主机之间通信的统计描述(指纹)和功能包方法。演示/框架可提供对数据的独特见解,并在搜索过程中对数据进行注释和模型修改,以更有效地识别受感染的主机。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号