An empirical analysis of NATE: Network Analysis of Anomalous Traffic Events

  • Authors:
  • Carol Taylor;Jim Alves-Foss

  • Affiliations:
  • University of Idaho, Moscow, Idaho;University of Idaho, Moscow, Idaho

  • Venue:
  • Proceedings of the 2002 workshop on New security paradigms
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents results of an empirical analysis of NATE (Network Analysis of Anomalous Traffic Events), a lightweight, anomaly based intrusion detection tool. Previous work was based on the simulated Lincoln Labs data set. Here, we show that NATE can operate under the constraints of real data inconsistencies. In addition, new TCP sampling and distance methods are presented. Differences between real and simulated data are discussed in the course of the analysis.