Integrating Traffics with Network Device Logs for Anomaly Detection

Joint Authors

Zhuo, Zhongliu
Hu, Teng
Liu, Xiaolei
Lu, Jiazhong
Lv, Fengmao
Zhang, Xiaosong
Deng, Wei

Source

Security and Communication Networks

Issue

Vol. 2019, Issue 2019 (31 Dec. 2019), pp.1-10, 10 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2019-06-13

Country of Publication

Egypt

No. of Pages

10

Main Subjects

Information Technology and Computer Science

Abstract EN

Advanced cyberattacks are often featured by multiple types, layers, and stages, with the goal of cheating the monitors.

Existing anomaly detection systems usually search logs or traffics alone for evidence of attacks but ignore further analysis about attack processes.

For instance, the traffic detection methods can only detect the attack flows roughly but fail to reconstruct the attack event process and reveal the current network node status.

As a result, they cannot fully model the complex multistage attack.

To address these problems, we present Traffic-Log Combined Detection (TLCD), which is a multistage intrusion analysis system.

Inspired by multiplatform intrusion detection techniques, we integrate traffics with network device logs through association rules.

TLCD correlates log data with traffic characteristics to reflect the attack process and construct a federated detection platform.

Specifically, TLCD can discover the process steps of a cyberattack attack, reflect the current network status, and reveal the behaviors of normal users.

Our experimental results over different cyberattacks demonstrate that TLCD works well with high accuracy and low false positive rate.

American Psychological Association (APA)

Lu, Jiazhong& Lv, Fengmao& Zhuo, Zhongliu& Zhang, Xiaosong& Liu, Xiaolei& Hu, Teng…[et al.]. 2019. Integrating Traffics with Network Device Logs for Anomaly Detection. Security and Communication Networks،Vol. 2019, no. 2019, pp.1-10.
https://search.emarefa.net/detail/BIM-1210488

Modern Language Association (MLA)

Lu, Jiazhong…[et al.]. Integrating Traffics with Network Device Logs for Anomaly Detection. Security and Communication Networks No. 2019 (2019), pp.1-10.
https://search.emarefa.net/detail/BIM-1210488

American Medical Association (AMA)

Lu, Jiazhong& Lv, Fengmao& Zhuo, Zhongliu& Zhang, Xiaosong& Liu, Xiaolei& Hu, Teng…[et al.]. Integrating Traffics with Network Device Logs for Anomaly Detection. Security and Communication Networks. 2019. Vol. 2019, no. 2019, pp.1-10.
https://search.emarefa.net/detail/BIM-1210488

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1210488