首页> 外文学位 >Identification of and automated support for an efficient covert channel analysis process.
【24h】

Identification of and automated support for an efficient covert channel analysis process.

机译:识别并自动支持有效的秘密渠道分析过程。

获取原文
获取原文并翻译 | 示例

摘要

Intrusion detection is a 'hard' problem. Finding malicious traffic such as covert channels against the background of normal network traffic is difficult, due to the false alarms raised by automated tools. One proposed solution to this detection problem is to provide a human analyst with a probability-based detection suite of tools which seek to characterize normal network traffic and create a model.;The Sliding Window Anomaly Detector (SWAD) can be used to analyse network traffic and separate it into anomalous and normal traffic. The malicious traffic is expected to be a subset of the anomalous traffic. Analysis of the anomalous traffic requires an analyst extract data from a database using hand-crafted queries. This process is poorly understood and undocumented.;The goal of this thesis is to identify the work processes and flows of the data sifting phase of intrusion detection using SWAD. The identified flows can then be used to increase operator efficiency, including the development of tools to support the analyst in the sifting process. The work flows and processes are documented for use in validation and for future research.;This research is validated through the creation of an analysis tool from a set of requirements extracted from the work flows. User testing will be used to show that the work flows can be utilized to create tools and train users to perform the sifting process in a manner that is more efficient than is currently used.;Keywords. Covert Channel Detection, Data Sifting, SWAD.
机译:入侵检测是一个“硬”问题。由于自动化工具会引发错误警报,因此很难在正常网络流量的背景下找到诸如隐蔽通道之类的恶意流量。解决此检测问题的一种建议解决方案是为人类分析人员提供基于概率的检测套件,这些工具旨在表征正常的网络流量并创建模型。滑动窗口异常检测器(SWAD)可用于分析网络流量并将其分为异常流量和正常流量。恶意流量预计将是异常流量的子集。对异常流量的分析需要分析师使用手工查询从数据库中提取数据。该过程了解甚少,没有文献记载。;本文的目的是识别使用SWAD进行入侵检测的数据筛选阶段的工作流程和流程。然后,可以将识别出的流程用于提高操作员效率,包括开发工具以在筛选过程中支持分析师。工作流程和过程都记录在案,以用于验证和将来的研究。该研究通过从工作流程中提取的一组需求中创建分析工具来进行验证。用户测试将用于显示工作流程可用于创建工具并训练用户以比当前使用的效率更高的方式执行筛选过程。隐蔽通道检测,数据筛选,SWAD。

著录项

  • 作者

    Forest, Kevin R.;

  • 作者单位

    Royal Military College of Canada (Canada).;

  • 授予单位 Royal Military College of Canada (Canada).;
  • 学科 Computer Science.
  • 学位 M.A.Sc.
  • 年度 2009
  • 页码 102 p.
  • 总页数 102
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号