首页> 外文会议>IEEE Military Communications Conference >Malware propagation in fully connected networks: A netflow-based analysis
【24h】

Malware propagation in fully connected networks: A netflow-based analysis

机译:全连接网络中的恶意软件传播:基于Netflow的分析

获取原文

摘要

Malware attacks have become ubiquitous in modern large data-centric networks. Therefore advanced malware threat detection and related countermeasures are an important paradigm in cybersecurity research. This work studies malware propagation in fully connected networks, where network topology plays a minimal role in lateral spread within the network. The live netflow and perimeter alert data used in this study contrasts with other previous works due to the unavailability of ground truth for any attack type. Important features calculated from the netflow data as well as a novel ring-based flow model are described. These are helpful in tracking possible malware flow within the network. The results show that relevant features can be used to draw inferences about the propagation of certain classes of malware attacks.
机译:恶意软件攻击已经在以现代大型数据为中心的网络中无处不在。因此,高级恶意软件威胁检测和相关对策是网络安全研究的重要范例。这项工作研究了在完全连接的网络中恶意软件的传播,其中网络拓扑在网络内部横向传播中起着最小的作用。本研究中使用的实时网络流量和周界警报数据与其他先前的工作形成了对比,原因是没有针对任何攻击类型的地面真实性信息。描述了根据净流量数据计算出的重要特征以及新颖的基于环的流量模型。这些有助于跟踪网络中可能的恶意软件流。结果表明,相关功能可用于推断某些类别的恶意软件攻击的传播。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号