首页> 外军国防科技报告 >ARL-TR-8578 - The Use of Packet Header Anomaly Detection in Lossy Network Traffic Compression for Network Intrusion Detection Applications | U.S. Army Research Laboratory
【2h】

ARL-TR-8578 - The Use of Packet Header Anomaly Detection in Lossy Network Traffic Compression for Network Intrusion Detection Applications | U.S. Army Research Laboratory

机译:ARL-TR-8578 - 在网络入侵检测应用中有损网络流量压缩中使用数据包报头异常检测美国陆军研究实验室

代理获取
代理获取并翻译 | 示例

摘要

This report describes efforts to employ a packet header anomaly detection algorithm to measure how unusual each packet is. A compression tool is written that compares this measure against a threshold, keeping only that traffic that is more unusual than the threshold. The Snort network intrusion detection tool is run against the data set to establish a baseline of alerts. It is then runagainst the compressed data set to discover how many alerts were lost or the alert loss rate. The threshold is lowered and the experiment repeated several times. The size of the data expressed as a percentage of the original size and the alert lost rate are plotted against these thresholds to show the threshold that provides the best compression with the acceptable alert loss.

著录项

  • 作者单位
  • 年(卷),期 2018(),
  • 年度 2018
  • 页码
  • 总页数 22
  • 原文格式 PDF
  • 正文语种
  • 中图分类
  • 网站名称 美国陆军研究实验室
  • 栏目名称 全部文件
  • 关键词

代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号