【24h】

A Thermodynamics-Based Model of Network Conversation Flux for Intrusion Detection

机译:基于热力学的网络会话通量入侵检测模型

获取原文
获取原文并翻译 | 示例

摘要

A novel system for conducting non-signature based, or pattemless, intrusion detection of computer networks is presented. This system uses principles of thermodynamics to model network conversation characteristics. Observing the properties of entropy, energy and temperature within the system develops a notion of baseline operating conditions. Perturbations in these properties are considered potential intrusions for further investigation. System functions are decomposed into a network sensing device, a real-time processing component and a forensics component State definitions for a variety of conditions are discussed. Finally, examples of valid intrusions and other network perturbations in real traffic collected in network operation center backbones are presented. Preliminary results indicate this system has significant potential for revealing anomalies in large network systems.
机译:提出了一种用于进行基于非签名或无模式的计算机网络入侵检测的新颖系统。该系统使用热力学原理对网络会话特征进行建模。观察系统内的熵,能量和温度的特性会得出基线工作条件的概念。这些特性的扰动被认为是潜在的入侵,需要进一步研究。系统功能被分解为网络传感设备,实时处理组件和取证组件讨论了各种条件的状态定义。最后,给出了在网络运营中心骨干网中收集的实际流量中的有效入侵和其他网络干扰的示例。初步结果表明,该系统具有揭示大型网络系统中异常现象的巨大潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号