Characterizing Network Flows for Detecting DNS, NTP, and SNMP Anomalies

Advances in intelligent systems and computing(2018)

引用 3|浏览0
暂无评分
摘要
Network security can never be assured fully as new attacks are reported every day. Characterizing such new attacks is a challenging task. For detecting anomalies based on specific services, it is desirable to find characteristic features for those service specific anomalies. In this paper, real-time flow-based network traffic captured from a university campus is studied to find if the traditional volume-based analysis of aggregated flows and service specific aggregated flows is useful in detecting service specific anomalies or not. Two existing techniques are also evaluated to find characteristic features of these anomalies. The service specific anomalies: DNS, NTP, and SNMP are considered for study in this paper.
更多
查看译文
关键词
Network flows, DNS tunnel, DNS amplification reflection, NTP, SNMP
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要