首页> 外文会议>International Conference on Information Security >SVision: A Network Host-Centered Anomaly Visualization Technique
【24h】

SVision: A Network Host-Centered Anomaly Visualization Technique

机译:SVISION:一种网络宿主的异常可视化技术

获取原文

摘要

We proposed a technique merged from a combination of both anomaly and graphical methods, for intrusion detection. The network is pictured as a community of hosts that exchange messages among themselves. Our aim is to graphically highlight those hosts that represent a possible threat for the network, so that a network administrator will be able to further explore the anomaly and decide upon the responses that are appropriate. We choose to test our view against the DARPA 99 intrusion detection and evaluation dataset since it provides labels which we can use to monitor our system. Experiments show our visualization technique as a possible alternative for detection of network intrusions, in particular Denial of Service (DoS) and Distributed-DoS attacks such as Ping Of Death, UDP storm, SSH Process Table, and Smurf, to name a few.
机译:我们提出了一种从两种异常和图形方法的组合合并的技术,用于入侵检测。该网络被描绘为交换消息之间的主机社区。我们的目标是以图形方式突出显示代表网络可能威胁的主机,以便网络管理员能够进一步探索异常并决定适当的响应。我们选择测试我们对DARPA 99入侵检测和评估数据集的视图,因为它提供了我们可以用于监视我们的系统的标签。实验表明我们的可视化技术作为检测网络入侵的可能替代方案,特别是拒绝服务(DOS)和分布式DOS攻击,例如死亡,UDP Storm,SSH流程表和SMURF,以命名几个。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号