首页> 美国政府科技报告 >Coordinated Anomaly Detection and Characterization in Wide Area Network Flows
【24h】

Coordinated Anomaly Detection and Characterization in Wide Area Network Flows

机译:广域网流量中的协调异常检测与表征

获取原文

摘要

The ability to quickly and accurately identify anomalous behavior in computer networks is essential to assure that they perform efficiently safely and reliably. The current standard in anomaly detection technology is autonomous packet level analysis that uses simple thresholds or rules to generate alerts While these systems are effective in detecting and identifying some types of anomalous behavior, networks are still far from being robust or reliable. In this project, we are pursuing research initiatives aimed at developing the next generation of anomaly detection infrastructures, methods and toots Our initial efforts have focused in two areas - measurement and characterization of general types of anomalous traffic (misconfigurations, failures, flash crowds, etc), and measurement and characterization of malicious network traffic (intrusions and attacks) Our focus is the former has been on applying multi-resolution analysis to IP flow data collected at our campus border router. Our focus in the latter has bean on using intrusion data collected from a large number of networks to identify malicious activity Both efforts have resulted in tools and systems that we will continue to develop. Our future efforts will emphasize expansion and refinement of coordinated detection methods and wide deployment of these capabilities across the 1Pv4 address space as well as in the wireless domain.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号