【24h】

Collaborative Attack Detection in High-Speed Networks

机译:高速网络中的协作攻击检测

获取原文

摘要

We present a multi-agent system designed to detect malicious traffic in high-speed networks. In order to match the performance requirements related to the traffic volume, the network traffic data is acquired by hardware accelerated probes in NetFlow format and preprocessed before processing by the detection agent. The proposed detection algorithm is based on extension of trust modeling techniques with representation of uncertain identities, context representation and implicit assumption that significant traffic anomalies are a result of potentially malicious action. In order to model the traffic, each of the cooperating agents uses an existing anomaly detection method, that are then correlated using a reputation mechanism. The output of the detection layer is presented to operator by a dedicated analyst interface agent, which retrieves additional information to facilitate incident analysis. Our performance results illustrate the potential of the combination of high-speed hardware with cooperative detection algorithms and advanced analyst interface.
机译:我们展示了一个旨在检测高速网络中恶意流量的多功能辅助系统。为了匹配与业务量相关的性能要求,网络流量数据由NetFlow格式的硬件加速探测器获取,并在通过检测代理进行处理之前预处理。所提出的检测算法基于具有不确定标识的表示,上下文表示和隐式假设的信任建模技术的扩展,即大量流量异常是潜在恶意动作的结果。为了模拟流量,每个协作剂使用现有的异常检测方法,然后使用声誉机制来相关。检测层的输出通过专用分析师接口代理向操作员提出,该代理检索附加信息以促进事件分析。我们的性能结果说明了高速硬件与协作检测算法和高级分析界面组合的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号