Integrating Traffics with Network Device Logs for Anomaly Detection
Joint Authors
Zhuo, Zhongliu
Hu, Teng
Liu, Xiaolei
Lu, Jiazhong
Lv, Fengmao
Zhang, Xiaosong
Deng, Wei
Source
Security and Communication Networks
Issue
Vol. 2019, Issue 2019 (31 Dec. 2019), pp.1-10, 10 p.
Publisher
Hindawi Publishing Corporation
Publication Date
2019-06-13
Country of Publication
Egypt
No. of Pages
10
Main Subjects
Information Technology and Computer Science
Abstract EN
Advanced cyberattacks are often featured by multiple types, layers, and stages, with the goal of cheating the monitors.
Existing anomaly detection systems usually search logs or traffics alone for evidence of attacks but ignore further analysis about attack processes.
For instance, the traffic detection methods can only detect the attack flows roughly but fail to reconstruct the attack event process and reveal the current network node status.
As a result, they cannot fully model the complex multistage attack.
To address these problems, we present Traffic-Log Combined Detection (TLCD), which is a multistage intrusion analysis system.
Inspired by multiplatform intrusion detection techniques, we integrate traffics with network device logs through association rules.
TLCD correlates log data with traffic characteristics to reflect the attack process and construct a federated detection platform.
Specifically, TLCD can discover the process steps of a cyberattack attack, reflect the current network status, and reveal the behaviors of normal users.
Our experimental results over different cyberattacks demonstrate that TLCD works well with high accuracy and low false positive rate.
American Psychological Association (APA)
Lu, Jiazhong& Lv, Fengmao& Zhuo, Zhongliu& Zhang, Xiaosong& Liu, Xiaolei& Hu, Teng…[et al.]. 2019. Integrating Traffics with Network Device Logs for Anomaly Detection. Security and Communication Networks،Vol. 2019, no. 2019, pp.1-10.
https://search.emarefa.net/detail/BIM-1210488
Modern Language Association (MLA)
Lu, Jiazhong…[et al.]. Integrating Traffics with Network Device Logs for Anomaly Detection. Security and Communication Networks No. 2019 (2019), pp.1-10.
https://search.emarefa.net/detail/BIM-1210488
American Medical Association (AMA)
Lu, Jiazhong& Lv, Fengmao& Zhuo, Zhongliu& Zhang, Xiaosong& Liu, Xiaolei& Hu, Teng…[et al.]. Integrating Traffics with Network Device Logs for Anomaly Detection. Security and Communication Networks. 2019. Vol. 2019, no. 2019, pp.1-10.
https://search.emarefa.net/detail/BIM-1210488
Data Type
Journal Articles
Language
English
Notes
Includes bibliographical references
Record ID
BIM-1210488