کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
4955807 1444363 2017 40 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Alert correlation framework for malware detection by anomaly-based packet payload analysis
ترجمه فارسی عنوان
چارچوب همبستگی هشدار برای تشخیص نرم افزارهای مخرب با استفاده از تجزیه و تحلیل بارهای بسته مبتنی بر آنومالی
کلمات کلیدی
همبستگی هشدار، ناهنجاری ها، سیستم تشخیص نفوذ، بد افزار، شبکه، ظرفیت ترابری،
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی
Intrusion detection based on identifying anomalies typically emits a large amount of reports about the malicious activities monitored; hence information gathered is difficult to manage. In this paper, an alert correlation system capable of dealing with this problem is introduced. The work carried out has focused on the study of a particular family of sensors, namely those which analyze the payload of network traffic looking for malware. Unlike conventional approaches, the information provided by the network packet headers is not taken into account. Instead, the proposed strategy considers the payload of the monitored traffic and the characteristics of the models built during the training of such detectors, in this way supporting the general-purpose incident management tools. It aims to analyze, classify and prioritize alerts issued, based on two criteria: the risk of threats being genuine and their nature. Incidences are studied both in a one-to-one and in a group context. This implies the consideration of two different processing layers: The first one allows fast reactions and resilience against certain adversarial attacks, and on the other hand, the deeper layer facilitates the reconstruction of attack scenarios and provides an overview of potential threats. Experiments conducted by analyzing real traffic demonstrated the effectiveness of the proposal.
ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Journal of Network and Computer Applications - Volume 97, 1 November 2017, Pages 11-22
نویسندگان
, , ,