首页> 外文会议>IFIP WG 11.9 International Conference on Digital Forensics >A NETWORK FORENSIC SCHEME USING CORRENTROPY-VARIATION FOR ATTACK DETECTION
【24h】

A NETWORK FORENSIC SCHEME USING CORRENTROPY-VARIATION FOR ATTACK DETECTION

机译:利用Cornertropy-Variation进行攻击检测的网络取证方案

获取原文

摘要

Network forensic techniques help track cyber attacks by monitoring and analyzing network traffic. However, due to the large volumes of data in modern networks and sophisticated attacks that mimic normal behavior and/or erase traces to avoid detection, network attack investigations demand intelligent and efficient network forensic techniques. This chapter proposes a network forensic scheme for monitoring and investigating network-based attacks. The scheme captures and stores network traffic data, selects important network traffic features using the chi-square statistic and detects anomalous events using a novel correntropy-variation technique. An evaluation of the network forensic scheme employing the UNSW-NB15 dataset demonstrates its utility and high performance compared with three state-of-the-art approaches.
机译:网络取证技术通过监视和分析网络流量来帮助跟踪网络攻击。但是,由于现代网络中的大量数据以及模仿正常行为和/或擦除痕迹以避免检测的复杂攻击,网络攻击调查需要智能且有效的网络取证技术。本章提出了一种用于监视和调查基于网络的攻击的网络取证方案。该方案捕获并存储网络流量数据,使用卡方统计量选择重要的网络流量特征,并使用新颖的熵变技术检测异常事件。对使用UNSW-NB15数据集的网络取证方案进行的评估表明,与三种最新方法相比,它的实用性和高性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号