메뉴 건너뛰기




Volumn , Issue , 2006, Pages 165-176

Is sampled data sufficient for anomaly detection?

Author keywords

Anomaly detection; Portscan; Sampling; Volume anomaly

Indexed keywords

ANOMALY DETECTION; HYPOTHESES TESTING; TRAFFIC ACCOUNTING METHODS; TRAFFIC FEATURES;

EID: 34547488856     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/1177080.1177102     Document Type: Conference Paper
Times cited : (176)

References (20)
  • 1
    • 34547422039 scopus 로고    scopus 로고
    • Cisco IOS Software NetFlow. http://www.cisco.com/warp/public/732/Tech/ nmp/ netflow/. [2] Juniper Networks: JUNOS 7.2 Software Documentation. http://www.juniper.net/techpubs/software/junos/ junos72/index.html.
    • Cisco IOS Software NetFlow. http://www.cisco.com/warp/public/732/Tech/ nmp/ netflow/. [2] Juniper Networks: JUNOS 7.2 Software Documentation. http://www.juniper.net/techpubs/software/junos/ junos72/index.html.
  • 2
    • 84858083684 scopus 로고    scopus 로고
    • Snort, http://www.snort.org.
    • Snort
  • 3
    • 0141427794 scopus 로고    scopus 로고
    • A Signal Analysis of Network Traffic Anomalies
    • Marseille, France, Nov
    • P. Barford, J. Kline, D. Plonka, and A. Ron. A Signal Analysis of Network Traffic Anomalies. In Proc. ACM SIGCOMM IMW'02, pages 71-82, Marseille, France, Nov. 2002.
    • (2002) Proc. ACM SIGCOMM IMW'02 , pp. 71-82
    • Barford, P.1    Kline, J.2    Plonka, D.3    Ron, A.4
  • 4
    • 0041534324 scopus 로고    scopus 로고
    • Characteristics of Network TRaffic Flow Anomalies
    • San Francisco, CA, USA, Nov
    • P. Barford and D. Plonka. Characteristics of Network TRaffic Flow Anomalies. In Proc. ACM SIGCOMM IMW'01, pages 69-73, San Francisco, CA, USA, Nov. 2001.
    • (2001) Proc. ACM SIGCOMM IMW'01 , pp. 69-73
    • Barford, P.1    Plonka, D.2
  • 6
    • 16344383315 scopus 로고    scopus 로고
    • Sampling for Passive Internet Measurement: A Review
    • N. Duffield. Sampling for Passive Internet Measurement: A Review. Statistical Science, 19(3):472-498, 2004.
    • (2004) Statistical Science , vol.19 , Issue.3 , pp. 472-498
    • Duffield, N.1
  • 7
    • 8344233039 scopus 로고    scopus 로고
    • Properties and Prediction of Flow Statistics from Sampled Packet Streams
    • Marseille, France, Nov
    • N. Duffield, C. Lund, and M. Thorup. Properties and Prediction of Flow Statistics from Sampled Packet Streams. In Proc. ACM SIGCOMM IMW'02, Marseille, France, Nov. 2002.
    • (2002) Proc. ACM SIGCOMM IMW'02
    • Duffield, N.1    Lund, C.2    Thorup, M.3
  • 8
    • 8344290018 scopus 로고    scopus 로고
    • Estimating Flow Distributions from Sampled Flow Statistics
    • Karlsruhe, Germany, Aug
    • N. Duffield, C. Lund, and M. Thorup. Estimating Flow Distributions from Sampled Flow Statistics. In Proc. ACM SIGCOMM'03, Karlsruhe, Germany, Aug. 2003.
    • (2003) Proc. ACM SIGCOMM'03
    • Duffield, N.1    Lund, C.2    Thorup, M.3
  • 10
    • 0141440878 scopus 로고    scopus 로고
    • New Directions in Traffic Measurement and Accounting
    • Pittsburgh, Pennsylvania, USA, Aug
    • C. Estan and G. Varghese. New Directions in Traffic Measurement and Accounting. In Proc. of SIGCOMM'02, Pittsburgh, Pennsylvania, USA, Aug. 2002.
    • (2002) Proc. of SIGCOMM'02
    • Estan, C.1    Varghese, G.2
  • 12
    • 19544362049 scopus 로고    scopus 로고
    • Inverting Sampled Traffic
    • Miami Beach, Florida, USA, Oct
    • N. Hohn and D. Veitch. Inverting Sampled Traffic. In Proc. ACM SIGCOMM IMC'03, Miami Beach, Florida, USA, Oct. 2003.
    • (2003) Proc. ACM SIGCOMM IMC'03
    • Hohn, N.1    Veitch, D.2
  • 14
    • 14944367082 scopus 로고    scopus 로고
    • Sketch-based Change Detection: Methods, Evaluation, and Applications
    • Miami Beach, Florida, USA, Oct
    • B. Krishnamurthy, S. Sen, Y. Zhang, and Y. Chen. Sketch-based Change Detection: Methods, Evaluation, and Applications. In Proc. ACM SIGCOMM IMCOS, Miami Beach, Florida, USA, Oct. 2003.
    • (2003) Proc. ACM SIGCOMM IMCOS
    • Krishnamurthy, B.1    Sen, S.2    Zhang, Y.3    Chen, Y.4
  • 15
    • 33746603312 scopus 로고    scopus 로고
    • Mining Anomalies Using Traffic Feature Distributions
    • Philadelphia, PA, USA, Aug
    • A. Lakhina, M. Crovella, and C. Diot. Mining Anomalies Using Traffic Feature Distributions. In Proc. ACM SIGCOMM '05, Philadelphia, PA, USA, Aug. 2005.
    • (2005) Proc. ACM SIGCOMM '05
    • Lakhina, A.1    Crovella, M.2    Diot, C.3
  • 16
    • 34547483645 scopus 로고    scopus 로고
    • J. Mai, A. Sridharan, C.-N. Chuah, T. Ye, and H. Zang. Impact of Packet Sampling on Portscan Detection. Technical Report RR06-ATL-043166, Sprint ATL, 2006. (accepted by IEEE JSAC Special Issue on Sampling the Internet).
    • J. Mai, A. Sridharan, C.-N. Chuah, T. Ye, and H. Zang. Impact of Packet Sampling on Portscan Detection. Technical Report RR06-ATL-043166, Sprint ATL, 2006. (accepted by IEEE JSAC Special Issue on Sampling the Internet).
  • 17
    • 85090433665 scopus 로고    scopus 로고
    • Snort - Lightweight Intrusion Detection for Networks
    • Seattle, WA, USA, Nov
    • M. Roesch. Snort - Lightweight Intrusion Detection for Networks. In Proc. 1999 USENIX LISA Conference, Seattle, WA, USA, Nov. 1999.
    • (1999) Proc. 1999 USENIX LISA Conference
    • Roesch, M.1
  • 20
    • 0043166339 scopus 로고    scopus 로고
    • Anomaly Detection in IP Networks
    • Aug
    • M. Thottan and C. Ji. Anomaly Detection in IP Networks. IEEE Trans, on Signal Processing, 51(8):2191-2204, Aug. 2003.
    • (2003) IEEE Trans, on Signal Processing , vol.51 , Issue.8 , pp. 2191-2204
    • Thottan, M.1    Ji, C.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.