科技报告详细信息
IP Profiling via Service Cluster Membership Vectors.
Bartoletti, A.
Technical Information Center Oak Ridge Tennessee
关键词: Clustering;    Network services;    Characterization;    Network traffic;    Detection;   
RP-ID  :  DE2009948968
学科分类:工程和技术(综合)
美国|英语
来源: National Technical Reports Library
PDF
【 摘 要 】

This study investigates the feasibility of establishing and maintaining a system of compact IP behavioral profiles as a robust means of computer anomaly definition and detection. These profiles are based upon the degree to which a systems (IPs) network traffic is distributed among stable characteristic clusters derived of the aggregate session traffic generated by each of the major network services. In short, an IPs profile represents its degree of membership in these derived service clusters. The goal is to quantify and rank behaviors that are outside of the statistical norm for the services in question, or present significant deviation from profile for individual client IPs. Herein, we establish stable clusters for accessible features of common session traffic, migrate these clusters over time, define IP behavior profiles with respect to these clusters, migrate individual IP profiles over time, and demonstrate the detection of IP behavioral changes in terms of deviation from profile.

【 预 览 】
附件列表
Files Size Format View
DE2009948968.pdf 2494KB PDF download
  文献评价指标  
  下载次数:23次 浏览次数:16次