메뉴 건너뛰기




Volumn 40, Issue 3, 2010, Pages 4-16

On Mitigating sampling-induced accuracy loss in traffic anomaly detection systems

Author keywords

Anomaly detection; Denial of service (DoS); Packet sampling; Portscan

Indexed keywords

ACCURACY LOSS; ANOMALY DETECTION; ANOMALY DETECTION SYSTEMS; ANOMALY DETECTOR; COMMUNICATION OVERHEADS; DATA SETS; DENIAL OF SERVICE; IN-LINE; INTERNET TRAFFIC; INTRUSION DETECTION ALGORITHMS; LOW COMPLEXITY; MALICIOUS PACKETS; MALICIOUS TRAFFIC; NEXT-HOP; PACKET SAMPLING; PORTSCAN; RANDOM SAMPLING; REALISTIC CONDITIONS; SAMPLED PACKET; SAMPLING RATES; SECURITY-AWARE; TRAFFIC ANALYSIS; TRAFFIC ANOMALIES;

EID: 78649866466     PISSN: 01464833     EISSN: 01464833     Source Type: Conference Proceeding    
DOI: 10.1145/1823844.1823846     Document Type: Conference Paper
Times cited : (21)

References (36)
  • 2
    • 33746603312 scopus 로고    scopus 로고
    • Mining anomalies using traffic feature distributions
    • A. Lakhina, M. Crovella, and C. Diot, "Mining Anomalies Using Traffic Feature Distributions," ACM SIGCOMM, 2005.
    • (2005) ACM SIGCOMM
    • Lakhina, A.1    Crovella, M.2    Diot, C.3
  • 7
    • 37049006312 scopus 로고    scopus 로고
    • Adaptive random sampling for total load estimation
    • B. Y. Choi, J. Park, and Z. L. Zhang, Adaptive random sampling for total load estimation," IEEE ICC, 2003.
    • (2003) IEEE ICC
    • Choi, B.Y.1    Park, J.2    Zhang, Z.L.3
  • 8
    • 78649816570 scopus 로고    scopus 로고
    • Properties and prediction of flow statistics from sampled packet streams
    • N. Duffield, C. Lund, and M. Thorup, Properties and prediction of flow statistics from sampled packet streams," ACM IMC, 2002.
    • (2002) ACM IMC
    • Duffield, N.1    Lund, C.2    Thorup, M.3
  • 9
    • 8344290018 scopus 로고    scopus 로고
    • Estimating flow distributions from sampled flow statistics
    • N. Duffield, C. Lund, and M. Thorup, Estimating Flow Distributions from Sampled Flow Statistics," ACM SIGCOMM, 2003.
    • (2003) ACM SIGCOMM
    • Duffield, N.1    Lund, C.2    Thorup, M.3
  • 10
    • 33947659323 scopus 로고    scopus 로고
    • Inverting sampled traffic
    • N. Hohn and D. Veitch, "Inverting Sampled Traffic," ACM IMC, 2003.
    • (2003) ACM IMC
    • Hohn, N.1    Veitch, D.2
  • 11
    • 33845614039 scopus 로고    scopus 로고
    • Impact of packet sampling on portscan detection
    • J. Mai, A. Sridharan, C. N. Chuah, H. Zang, and T. Ye, "Impact of packet sampling on portscan detection," IEEE J. SAC, 24(12):2285-2298, 2006.
    • (2006) IEEE J. SAC , vol.24 , Issue.12 , pp. 2285-2298
    • Mai, J.1    Sridharan, A.2    Chuah, C.N.3    Zang, H.4    Ye, T.5
  • 15
    • 8344261545 scopus 로고    scopus 로고
    • PacketScore: Statistics-based overload control against distributed denial-of-service attacks
    • Y. Kim, W. C. Lau, M. C. Chuah, and H. J. Chao, "PacketScore: Statistics-based Overload Control against Distributed Denial-of-Service Attacks," IEEE INFOCOM, 2004.
    • (2004) IEEE INFOCOM
    • Kim, Y.1    Lau, W.C.2    Chuah, M.C.3    Chao, H.J.4
  • 16
    • 33749824252 scopus 로고    scopus 로고
    • ALPi: A DDoS defense system for high-speed networks
    • P. E. Ayres, H. Sun, and H. J. Chao, "ALPi: A DDoS Defense System for High-Speed Networks," IEEE J. SAC, 24(10):1864-1876, 2006.
    • (2006) IEEE J. SAC , vol.24 , Issue.10 , pp. 1864-1876
    • Ayres, P.E.1    Sun, H.2    Chao, H.J.3
  • 17
    • 33745605036 scopus 로고    scopus 로고
    • Detecting anomalies in network traffic using maximum entropy estimation
    • Y. Gu, A. McCullum, and D. Towsley, "Detecting anomalies in network traffic using maximum entropy estimation," ACM IMC, 2005.
    • (2005) ACM IMC
    • Gu, Y.1    McCullum, A.2    Towsley, D.3
  • 18
    • 26844466732 scopus 로고    scopus 로고
    • Fast detection of scanning worm infections
    • S. E. Schechter, J. Jung, and A. W. Berger, "Fast detection of scanning worm infections," RAID, 2004.
    • (2004) RAID
    • Schechter, S.E.1    Jung, J.2    Berger, A.W.3
  • 19
    • 0141441130 scopus 로고    scopus 로고
    • PHAD: Packet header anomaly detection for indentifying hostile network traffic
    • CS- 2001-4
    • M. V. Mahoney and P. K. Chan, "PHAD: Packet Header Anomaly Detection for Indentifying Hostile Network Traffic," Technical Report, Florida Tech., CS-2001-4.
    • Technical Report, Florida Tech.
    • Mahoney, M.V.1    Chan, P.K.2
  • 20
  • 21
    • 4544360452 scopus 로고    scopus 로고
    • New directions in traffic measurement and accounting
    • C. Estan and G. Varghese, "New Directions in Traffic Measurement and Accounting," ACM SIGCOMM, 2002.
    • (2002) ACM SIGCOMM
    • Estan, C.1    Varghese, G.2
  • 22
    • 78649816570 scopus 로고    scopus 로고
    • Properties and prediction of flow statistics from sampled packet streams
    • N. Duffield, C. Lund, and M. Thorup, "Properties and Prediction of Flow Statistics from Sampled Packet Streams," ACM IMW, 2002.
    • (2002) ACM IMW
    • Duffield, N.1    Lund, C.2    Thorup, M.3
  • 23
    • 1242330656 scopus 로고    scopus 로고
    • A signal analysis of network traffic anomalies
    • P. Barford, J. Kline, D. Plonka, and A. Ron, "A Signal Analysis of Network Traffic Anomalies," ACM IMW, 2002.
    • (2002) ACM IMW
    • Barford, P.1    Kline, J.2    Plonka, D.3    Ron, A.4
  • 26
    • 78649872778 scopus 로고    scopus 로고
    • Reducing false alarm rate in anomaly detection with layered filtering
    • R. Pokrywka, "Reducing False Alarm Rate in Anomaly Detection with Layered Filtering," ICCS, 2008.
    • (2008) ICCS
    • Pokrywka, R.1
  • 27
    • 61749083929 scopus 로고    scopus 로고
    • McPAD: A multiple classifler system for accurate payload-based anomaly detection
    • R. Perdisci, D. Ariu, P. Fogla, G. Giacinto, W. Lee, "McPAD: A multiple classifler system for accurate payload-based anomaly detection", Computer Networks, 2009.
    • (2009) Computer Networks
    • Perdisci, R.1    Ariu, D.2    Fogla, P.3    Giacinto, G.4    Lee, W.5
  • 29
    • 33845633068 scopus 로고    scopus 로고
    • Sketch guided sampling-using on-line estimates of flow size for adaptive data collection
    • A. Kumar and J. Xu, "Sketch Guided Sampling-Using On-Line Estimates of Flow Size for Adaptive Data Collection," IEEE INFOCOM, 2006.
    • (2006) IEEE INFOCOM
    • Kumar, A.1    Xu, J.2
  • 30
    • 36949004950 scopus 로고    scopus 로고
    • ProgME: Towards programmable network measurement
    • L. Yuan, C. Chuah, and P. Mohapatra, "ProgME: Towards Programmable Network MEasurement," ACM SIGCOMM, 2007.
    • (2007) ACM SIGCOMM
    • Yuan, L.1    Chuah, C.2    Mohapatra, P.3
  • 34
    • 84855831261 scopus 로고    scopus 로고
    • LBNL/ICSI Dataset, http://www.icir.org/enterprise-tracing/download.html.
    • LBNL/ICSI Dataset
  • 35
    • 78249285809 scopus 로고    scopus 로고
    • Endpoint Dataset, http://www.wisnet.seecs.edu.pk/projects/ENS/DataSets. html.
    • Endpoint Dataset


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.