Detecting Advanced Network Threats Using a Similarity Search - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

Detecting Advanced Network Threats Using a Similarity Search

Milan Čermák
  • Fonction : Auteur
  • PersonId : 1022575
Pavel Čeleda
  • Fonction : Auteur
  • PersonId : 994058

Résumé

In this paper, we propose a novel approach for the detection of advanced network threats. We combine knowledge-based detections with similarity search techniques commonly utilized for automated image annotation. This unique combination could provide effective detection of common network anomalies together with their unknown variants. In addition, it offers a similar approach to network data analysis as a security analyst does. Our research is focused on understanding the similarity of anomalies in network traffic and their representation within complex behaviour patterns. This will lead to a proposal of a system for the real-time analysis of network data based on similarity. This goal should be achieved within a period of three years as a part of a PhD thesis.
Fichier principal
Vignette du fichier
385745_1_En_14_Chapter.pdf (236.31 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01632739 , version 1 (10-11-2017)

Licence

Paternité

Identifiants

Citer

Milan Čermák, Pavel Čeleda. Detecting Advanced Network Threats Using a Similarity Search. 10th IFIP International Conference on Autonomous Infrastructure, Management and Security (AIMS), Jun 2016, Munich, Germany. pp.137-141, ⟨10.1007/978-3-319-39814-3_14⟩. ⟨hal-01632739⟩
29 Consultations
101 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More