谷歌浏览器插件
订阅小程序
在清言上使用

FLAME: A Flow-Level Anomaly Modeling Engine.

CSET'08: Proceedings of the conference on Cyber security experimentation and test(2008)

引用 23|浏览28
暂无评分
摘要
There are several remaining open questions in the area of flow-based anomaly detection, e.g., how to do meaningful evaluations of anomaly detection mechanisms; how to get conclusive information about the origin and nature of an anomaly; or how to detect low intensity attacks. In order to answer these questions, network traffic traces that are representative for a specific test environment, and that contain anomalies with selected characteristics are a prerequisite. In this work, we present flame, a tool for injection of hand-crafted anomalies into a given background traffic trace. This tool combines the controllability offered by simulation with the realism provided by captured traffic traces. We present the design and prototype implementation of flame, and show how it is applied to inject three example anomalies into a given flow trace. We believe that flame can contribute significantly to the development and evaluation of advanced anomaly detection mechanisms.
更多
查看译文
关键词
advanced anomaly detection mechanism,anomaly detection mechanism,example anomaly,flow-based anomaly detection,hand-crafted anomaly,background traffic trace,network traffic trace,present flame,traffic trace,flow trace,flow-level anomaly modeling engine
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要