Activity Monitoring for large honeynets and network telescopes - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Article Dans Une Revue International Journal On Advances in Systems and Measurements Année : 2008

Activity Monitoring for large honeynets and network telescopes

Résumé

This paper proposes a new distributed monitoring approach based on the notion of centrality of a graph and its evolution in time. We consider an activity profiling method for a distributed monitoring platform and illustrate its usage in two different target deployments. The first one concerns the monitoring of a distributed honeynet, while the second deployment target is the monitoring of a large network telescope. The central concept underlying our work are the intersection graphs and a centrality based locality statistics. These graphs have not been used widely in the field of network security. The advantage of this method is that analyzing aggregated activity data is possible by considering the curve of the maximum locality statistics and that important change point moments are well identified.
Fichier principal
Vignette du fichier
ijasm.pdf (1.05 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00392566 , version 1 (01-12-2009)

Identifiants

  • HAL Id : inria-00392566 , version 1

Citer

Jérôme François, Radu State, Olivier Festor. Activity Monitoring for large honeynets and network telescopes. International Journal On Advances in Systems and Measurements, 2008, 1 (1), pp.1-13. ⟨inria-00392566⟩
141 Consultations
340 Téléchargements

Partager

Gmail Facebook X LinkedIn More