Learning Rules for Anomaly Detection of Hostile Network恶意网络异常检测的学习规则.pptVIP

  • 4
  • 0
  • 约3.88千字
  • 约 16页
  • 2017-03-07 发布于上海
  • 举报

Learning Rules for Anomaly Detection of Hostile Network恶意网络异常检测的学习规则.ppt

Learning Rules for Anomaly Detection of Hostile Network恶意网络异常检测的学习规则

Learning Rules for Anomaly Detection of Hostile Network Traffic Matthew V. Mahoney and Philip K. Chan Florida Institute of Technology Problem: How to detect novel intrusions in network traffic given only a model of normal traffic Normal web server request GET /index.html HTTP/1.0 Code Red II worm GET /default.ida?NNNNNNNNN… What has been done Firewalls Can’t block attacks on open ports (web, mail, DNS) Signature Detection (SNORT, BRO) Hand coded rules (search for “default.ida?NNN”) Can’t detect new attacks Anomaly Detection (eBayes, ADAM, SPADE) Learn rules from normal traffic for low

文档评论(0)

1亿VIP精品文档

相关文档