Traffic pattern analysis for distributed anomaly detection

  • Authors:
  • Grzegorz Kolaczek;Krzysztof Juszczyszyn

  • Affiliations:
  • Institute of Informatics, Wroclaw University of Technology, Wroclaw, Poland;Institute of Informatics, Wroclaw University of Technology, Wroclaw, Poland

  • Venue:
  • PPAM'11 Proceedings of the 9th international conference on Parallel Processing and Applied Mathematics - Volume Part II
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Network anomalies refer to situations when observed network traffic deviate from normal network behaviour. In this paper, we propose a general framework which assumes the use of many different attack detection methods and show a way to integrate their results. We checked our approach by the use of network topology analysis methods applied to communication graphs. Based on this evaluation, we have proposed a measure called the AttackScore, which assesses the risk of an on-going attack and distinguishes between the effectiveness of the analytic measures used to detect it.