首页> 外文会议>Recent advances in intrusion detection >On the Limits of Payload-Oblivious Network Attack Detection
【24h】

On the Limits of Payload-Oblivious Network Attack Detection

机译:关于有效负载隐匿性网络攻击检测的限制

获取原文
获取原文并翻译 | 示例

摘要

We introduce a methodology for evaluating network intrusion detection systems using an observable attack space, which is a parameterized representation of a type of attack that can be observed in a particular type of log data. Using the observable attack space for log data that does not include payload (e.g., NetFlow data), we evaluate the effectiveness of five proposed detectors for bot harvesting and scanning attacks, in terms of their ability (even when used in conjunction) to deter the attacker from reaching his goals. We demonstrate the ranges of attack parameter values that would avoid detection, or rather that would require an inordinately high number of false alarms in order to detect them consistently.
机译:我们介绍一种使用可观察到的攻击空间评估网络入侵检测系统的方法,该方法是可以在特定类型的日志数据中观察到的攻击类型的参数化表示。使用不包含有效负载的日志数据的可观察攻击空间(例如NetFlow数据),我们就五个建议的检测器对僵尸程序捕获和扫描攻击的有效性(即使结合使用)评估了其有效性(即使结合使用)攻击者无法达到目标。我们演示了攻击参数值的范围,这些范围将避免检测,或者需要不计其数的错误警报才能一致地检测到它们。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号