메뉴 건너뛰기




Volumn 38, Issue 4, 2008, Pages 183-194

Enriching network security analysis with time travel

Author keywords

Forensics; Intrusion detection; Packet capture

Indexed keywords

FORENSICS; HEAVY-TAILED; INDEXING AND RETRIEVALS; NETWORK FLOWS; NETWORK SECURITY ANALYSIS; NETWORK TRAFFICS; OFFLINE; PACKET CAPTURE; PERFORMANCE EVALUATIONS; PROOF OF PRINCIPLES; REAL-TIME NETWORKS; RECORDING PARAMETERS; RETROSPECTIVE ANALYSIS; STAND -ALONE; TIME MACHINES; TIME TRAVELS; TRAFFIC STREAMS;

EID: 65249091864     PISSN: 01464833     EISSN: 01464833     Source Type: Conference Proceeding    
DOI: 10.1145/1402946.1402980     Document Type: Conference Paper
Times cited : (59)

References (27)
  • 1
    • 69649094907 scopus 로고    scopus 로고
    • Full Packet Capture and Offline Analysis on 1 and 10 Gb/s Networks
    • Tech. Rep. HPL-2006-156, HP Labs, 2006
    • ANDERSON, E., AND ARLITT, M. Full Packet Capture and Offline Analysis on 1 and 10 Gb/s Networks. Tech. Rep. HPL-2006-156, HP Labs, 2006.
    • ANDERSON, E.1    ARLITT, M.2
  • 3
    • 80051948268 scopus 로고    scopus 로고
    • Remembrance of Streams Past: Overload-sensitive Management of Archived Streams
    • CHANDRASEKARAN, S., AND FRANKLIN, M. Remembrance of Streams Past: Overload-sensitive Management of Archived Streams. In Proc. Very Large Data Bases (2004).
    • (2004) Proc. Very Large Data Bases
    • CHANDRASEKARAN, S.1    FRANKLIN, M.2
  • 6
    • 84868933886 scopus 로고    scopus 로고
    • CoMo. http://como.sourceforge.net.
    • CoMo
  • 8
    • 65249179384 scopus 로고    scopus 로고
    • CRANOR, C., JOHNSON, T., AND SPATSCHECK, O. Gigascope: A Stream Database for Network Applications. In Proc. SIGMOD (2003).
    • CRANOR, C., JOHNSON, T., AND SPATSCHECK, O. Gigascope: A Stream Database for Network Applications. In Proc. SIGMOD (2003).
  • 12
    • 65249164757 scopus 로고    scopus 로고
    • ENDACE MEASUREMENT SYSTEMS. http://www.endace.com/, 2008.
    • ENDACE MEASUREMENT SYSTEMS. http://www.endace.com/, 2008.
  • 13
    • 67650317025 scopus 로고    scopus 로고
    • GONZALEZ, J. M., PAXSON, V., AND WEAVER, N. Shunting: A Hardware/Software Architecture for Flexible, High-performance Network Intrusion Prevention. In Proc. 14th ACM Conf. on Comp, and Comm. Security (2007).
    • GONZALEZ, J. M., PAXSON, V., AND WEAVER, N. Shunting: A Hardware/Software Architecture for Flexible, High-performance Network Intrusion Prevention. In Proc. 14th ACM Conf. on Comp, and Comm. Security (2007).
  • 15
    • 84878718671 scopus 로고    scopus 로고
    • Building a Time Machine for Efficient Recording and Retrieval of High-Volume Network Traffic (Short Paper)
    • KORNEXL, S., PAXSON, V., DREGER, H., FELDMANN, A., AND SOMMER, R. Building a Time Machine for Efficient Recording and Retrieval of High-Volume Network Traffic (Short Paper). In Proc. ACM SIGCOMM IMC (2005).
    • (2005) Proc. ACM SIGCOMM IMC
    • KORNEXL, S.1    PAXSON, V.2    DREGER, H.3    FELDMANN, A.4    SOMMER, R.5
  • 17
    • 0030384024 scopus 로고    scopus 로고
    • On the Relationship Between File Sizes, Transport Protocols, and Self-similar Network Traffic
    • PARK, K., KIM, G., AND CROVELLA, M. On the Relationship Between File Sizes, Transport Protocols, and Self-similar Network Traffic. In Proc. ICNP '96 (1996).
    • (1996) Proc. ICNP '96
    • PARK, K.1    KIM, G.2    CROVELLA, M.3
  • 18
    • 0033295259 scopus 로고    scopus 로고
    • PAXSON, V. Bro: A System for Detecting Network Intruders in Real-Time. Comp. Networks 31, 23-24 (1999).
    • PAXSON, V. Bro: A System for Detecting Network Intruders in Real-Time. Comp. Networks 31, 23-24 (1999).
  • 23
    • 84868928777 scopus 로고    scopus 로고
    • SHANMUGASUNDARAM, K., MEMON, N., SAVANT, A., AND BRÖNNIMANN, H. ForNet: A Distributed Forensics Network. In Proc. Workshop on Math. Methods, Models and Architectures for Comp. Networks Security (2003).
    • SHANMUGASUNDARAM, K., MEMON, N., SAVANT, A., AND BRÖNNIMANN, H. ForNet: A Distributed Forensics Network. In Proc. Workshop on Math. Methods, Models and Architectures for Comp. Networks Security (2003).


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.