Integrating Traffics with Network Device Logs for Anomaly Detection

المؤلفون المشاركون

Zhuo, Zhongliu
Hu, Teng
Liu, Xiaolei
Lu, Jiazhong
Lv, Fengmao
Zhang, Xiaosong
Deng, Wei

المصدر

Security and Communication Networks

العدد

المجلد 2019، العدد 2019 (31 ديسمبر/كانون الأول 2019)، ص ص. 1-10، 10ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2019-06-13

دولة النشر

مصر

عدد الصفحات

10

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Advanced cyberattacks are often featured by multiple types, layers, and stages, with the goal of cheating the monitors.

Existing anomaly detection systems usually search logs or traffics alone for evidence of attacks but ignore further analysis about attack processes.

For instance, the traffic detection methods can only detect the attack flows roughly but fail to reconstruct the attack event process and reveal the current network node status.

As a result, they cannot fully model the complex multistage attack.

To address these problems, we present Traffic-Log Combined Detection (TLCD), which is a multistage intrusion analysis system.

Inspired by multiplatform intrusion detection techniques, we integrate traffics with network device logs through association rules.

TLCD correlates log data with traffic characteristics to reflect the attack process and construct a federated detection platform.

Specifically, TLCD can discover the process steps of a cyberattack attack, reflect the current network status, and reveal the behaviors of normal users.

Our experimental results over different cyberattacks demonstrate that TLCD works well with high accuracy and low false positive rate.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Lu, Jiazhong& Lv, Fengmao& Zhuo, Zhongliu& Zhang, Xiaosong& Liu, Xiaolei& Hu, Teng…[et al.]. 2019. Integrating Traffics with Network Device Logs for Anomaly Detection. Security and Communication Networks،Vol. 2019, no. 2019, pp.1-10.
https://search.emarefa.net/detail/BIM-1210488

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Lu, Jiazhong…[et al.]. Integrating Traffics with Network Device Logs for Anomaly Detection. Security and Communication Networks No. 2019 (2019), pp.1-10.
https://search.emarefa.net/detail/BIM-1210488

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Lu, Jiazhong& Lv, Fengmao& Zhuo, Zhongliu& Zhang, Xiaosong& Liu, Xiaolei& Hu, Teng…[et al.]. Integrating Traffics with Network Device Logs for Anomaly Detection. Security and Communication Networks. 2019. Vol. 2019, no. 2019, pp.1-10.
https://search.emarefa.net/detail/BIM-1210488

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1210488