메뉴 건너뛰기




Volumn , Issue , 2009, Pages 424-432

Rule-based anomaly detection on IP flows

Author keywords

[No Author keywords available]

Indexed keywords

ANOMALY DETECTION; APPLICATION AREA; FEATURE VECTORS; FLOW LEVEL; FLOW STATISTICS; HIGH-SPEED; IP FLOW; MACHINE-LEARNING; NETWORK APPLICATIONS; NETWORK LOCATION; PACKET CLASSIFICATION; PACKET LEVEL; PACKET-BASED; PAYLOAD INFORMATION; PREDICTION ACCURACY; PROOF OF CONCEPT; RULE BASED; SERVICE PROVIDER NETWORKS; SYSTEM ARCHITECTURES; TRAFFIC ANOMALIES;

EID: 70349687064     PISSN: 0743166X     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1109/INFCOM.2009.5061947     Document Type: Conference Paper
Times cited : (54)

References (19)
  • 2
    • 70349664112 scopus 로고    scopus 로고
    • "Snort," http://www.snort.org.
  • 3
    • 84871993728 scopus 로고    scopus 로고
    • "Cisco netflow. http://www.cisco.com/warp/public/732/netflow/."
    • Cisco netflow
  • 5
    • 33847290520 scopus 로고    scopus 로고
    • Mining anomalies using traffic feature distributions
    • A. Lakhina, M. Crovella, and C. Diot, "Mining anomalies using traffic feature distributions," in SIGCOMM '05, 2005, pp. 217-228.
    • (2005) SIGCOMM '05 , pp. 217-228
    • Lakhina, A.1    Crovella, M.2    Diot, C.3
  • 6
    • 34250801472 scopus 로고    scopus 로고
    • A hybrid machine learning approach to network anomaly detection
    • T. Shon and J. Moon, "A hybrid machine learning approach to network anomaly detection," Inf. Sci., vol. 177, no. 18, pp. 3799-3821, 2007.
    • (2007) Inf. Sci , vol.177 , Issue.18 , pp. 3799-3821
    • Shon, T.1    Moon, J.2
  • 7
    • 85092755815 scopus 로고    scopus 로고
    • Machine learning approaches to network anomaly detection
    • T. Ahmed, B. Oreshkin, and M. J. Coates, "Machine learning approaches to network anomaly detection," in Proc. SysML, 2007.
    • (2007) Proc. SysML
    • Ahmed, T.1    Oreshkin, B.2    Coates, M.J.3
  • 8
    • 34250752040 scopus 로고    scopus 로고
    • Combining filtering and statistical methods for anomaly detection
    • A. Soule, K. Salamatian, and N. Taft, "Combining filtering and statistical methods for anomaly detection," in IMC '05, 2005, pp. 1-14.
    • (2005) IMC '05 , pp. 1-14
    • Soule, A.1    Salamatian, K.2    Taft, N.3
  • 9
    • 70349114770 scopus 로고    scopus 로고
    • Network anomography
    • New York, NY, USA: ACM
    • Y. Zhang, Z. Ge, A. Greenberg, and M. Roughan, "Network anomography," in IMC '05. New York, NY, USA: ACM, 2005, pp. 1-14.
    • (2005) IMC '05 , pp. 1-14
    • Zhang, Y.1    Ge, Z.2    Greenberg, A.3    Roughan, M.4
  • 12
    • 34548118248 scopus 로고    scopus 로고
    • Offline/realtime traffic classification using semi-supervised learning
    • J. Erman, A. Mahanti, M. F. Arlitt, I. Cohen, and C. L. Williamson, "Offline/realtime traffic classification using semi-supervised learning," Perform. Eval., vol. 64, no. 9-12, pp. 1194-1213, 2007.
    • (2007) Perform. Eval , vol.64 , Issue.9-12 , pp. 1194-1213
    • Erman, J.1    Mahanti, A.2    Arlitt, M.F.3    Cohen, I.4    Williamson, C.L.5
  • 13
    • 84869166587 scopus 로고    scopus 로고
    • Internet traffic classification using bayesian analysis
    • A. Moore and D. Zuev, "Internet traffic classification using bayesian analysis," in Sigmetrics, 2005.
    • (2005) Sigmetrics
    • Moore, A.1    Zuev, D.2
  • 16
    • 0033281701 scopus 로고    scopus 로고
    • Improved boosting algorithms using confidence-rated predictions
    • R. E. Schapire and Y. Singer, "Improved boosting algorithms using confidence-rated predictions," Machine Learning, vol. 37, no. 3, pp. 297-336, 1999.
    • (1999) Machine Learning , vol.37 , Issue.3 , pp. 297-336
    • Schapire, R.E.1    Singer, Y.2
  • 17
    • 14344254638 scopus 로고    scopus 로고
    • Performance Guarantees for Regularized Maximum Entropy Density Estimation
    • Banff, Canada: Springer Verlag
    • M. Dudik, S. Phillips, and R. E. Schapire, "Performance Guarantees for Regularized Maximum Entropy Density Estimation," in Proceedings of COLT'04. Banff, Canada: Springer Verlag, 2004.
    • (2004) Proceedings of COLT'04
    • Dudik, M.1    Phillips, S.2    Schapire, R.E.3
  • 19
    • 0033295259 scopus 로고    scopus 로고
    • Bro: A System for Detecting Network Intruders in Real-Time
    • Dec
    • V. Paxson, "Bro: A System for Detecting Network Intruders in Real-Time," Computer Networks, vol. 31, pp. 2435-2463, Dec. 1999.
    • (1999) Computer Networks , vol.31 , pp. 2435-2463
    • Paxson, V.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.