Matches in SemOpenAlex for { <https://semopenalex.org/work/W1485062015> ?p ?o ?g. }
Showing items 1 to 97 of
97
with 100 items per page.
- W1485062015 endingPage "102" @default.
- W1485062015 startingPage "71" @default.
- W1485062015 abstract "Effective network security administration depends to a great extent on having accurate, concise, high-quality information about malicious activity in one’s network. Honeynets can potentially provide such detailed information, but the volume and diversity of this data can prove overwhelming. We explore ways to integrate honeypot data into daily network security monitoring with a goal of sufficiently classifying and summarizing the data to provide ongoing “situational awareness.” We present such a system, built using the Bro network intrusion detection system coupled with statistical analysis of numerous honeynet “events”, and discuss experiences drawn from many months of operation. In particular, we develop methodologies by which sites receiving such probes can infer—using purely local observation—information about the probing activity: What scanning strategies does the probing employ? Is this an attack that specifically targets the site, or is the site only incidentally probed as part of a larger, indiscriminant attack? One key aspect of this environment is its ability to provide insight into large-scale events. We look at the problem of accurately classifying botnet sweeps and worm outbreaks, which turns out to be difficult to grapple with due to the high dimensionality of such incidents. Using datasets collected during a number of these events, we explore the utility of several analysis methods, finding that when used together they show good potential for contributing towards effective situational awareness. Our analysis draws upon extensive honeynet data to explore the prevalence of different types of scanning, including properties, such as trend, uniformity, coordination, and darknet-avoidance. In addition, we design schemes to extrapolate the global properties of scanning events (e.g., total population and target scope) as inferred from the limited local view of a honeynet. Cross-validating with data from DShield shows that such inferences exhibit promising accuracy." @default.
- W1485062015 created "2016-06-24" @default.
- W1485062015 creator A5002219113 @default.
- W1485062015 creator A5035475219 @default.
- W1485062015 creator A5037458498 @default.
- W1485062015 creator A5043427561 @default.
- W1485062015 creator A5085002486 @default.
- W1485062015 creator A5091296600 @default.
- W1485062015 date "2009-09-30" @default.
- W1485062015 modified "2023-09-24" @default.
- W1485062015 title "Employing Honeynets For Network Situational Awareness" @default.
- W1485062015 cites W1532313454 @default.
- W1485062015 cites W1563061804 @default.
- W1485062015 cites W2031006315 @default.
- W1485062015 cites W2033811087 @default.
- W1485062015 cites W2083477206 @default.
- W1485062015 cites W2096030967 @default.
- W1485062015 cites W2100198871 @default.
- W1485062015 cites W2102671922 @default.
- W1485062015 cites W2126059122 @default.
- W1485062015 cites W2138845856 @default.
- W1485062015 cites W2158060559 @default.
- W1485062015 cites W3216912485 @default.
- W1485062015 doi "https://doi.org/10.1007/978-1-4419-0140-8_5" @default.
- W1485062015 hasPublicationYear "2009" @default.
- W1485062015 type Work @default.
- W1485062015 sameAs 1485062015 @default.
- W1485062015 citedByCount "24" @default.
- W1485062015 countsByYear W14850620152012 @default.
- W1485062015 countsByYear W14850620152013 @default.
- W1485062015 countsByYear W14850620152014 @default.
- W1485062015 countsByYear W14850620152015 @default.
- W1485062015 countsByYear W14850620152016 @default.
- W1485062015 countsByYear W14850620152017 @default.
- W1485062015 countsByYear W14850620152019 @default.
- W1485062015 countsByYear W14850620152021 @default.
- W1485062015 countsByYear W14850620152022 @default.
- W1485062015 crossrefType "book-chapter" @default.
- W1485062015 hasAuthorship W1485062015A5002219113 @default.
- W1485062015 hasAuthorship W1485062015A5035475219 @default.
- W1485062015 hasAuthorship W1485062015A5037458498 @default.
- W1485062015 hasAuthorship W1485062015A5043427561 @default.
- W1485062015 hasAuthorship W1485062015A5085002486 @default.
- W1485062015 hasAuthorship W1485062015A5091296600 @default.
- W1485062015 hasConcept C110875604 @default.
- W1485062015 hasConcept C124101348 @default.
- W1485062015 hasConcept C127413603 @default.
- W1485062015 hasConcept C136764020 @default.
- W1485062015 hasConcept C145804949 @default.
- W1485062015 hasConcept C146978453 @default.
- W1485062015 hasConcept C17744445 @default.
- W1485062015 hasConcept C182590292 @default.
- W1485062015 hasConcept C191267431 @default.
- W1485062015 hasConcept C199539241 @default.
- W1485062015 hasConcept C22735295 @default.
- W1485062015 hasConcept C2522767166 @default.
- W1485062015 hasConcept C26517878 @default.
- W1485062015 hasConcept C35525427 @default.
- W1485062015 hasConcept C38652104 @default.
- W1485062015 hasConcept C41008148 @default.
- W1485062015 hasConcept C9114305 @default.
- W1485062015 hasConceptScore W1485062015C110875604 @default.
- W1485062015 hasConceptScore W1485062015C124101348 @default.
- W1485062015 hasConceptScore W1485062015C127413603 @default.
- W1485062015 hasConceptScore W1485062015C136764020 @default.
- W1485062015 hasConceptScore W1485062015C145804949 @default.
- W1485062015 hasConceptScore W1485062015C146978453 @default.
- W1485062015 hasConceptScore W1485062015C17744445 @default.
- W1485062015 hasConceptScore W1485062015C182590292 @default.
- W1485062015 hasConceptScore W1485062015C191267431 @default.
- W1485062015 hasConceptScore W1485062015C199539241 @default.
- W1485062015 hasConceptScore W1485062015C22735295 @default.
- W1485062015 hasConceptScore W1485062015C2522767166 @default.
- W1485062015 hasConceptScore W1485062015C26517878 @default.
- W1485062015 hasConceptScore W1485062015C35525427 @default.
- W1485062015 hasConceptScore W1485062015C38652104 @default.
- W1485062015 hasConceptScore W1485062015C41008148 @default.
- W1485062015 hasConceptScore W1485062015C9114305 @default.
- W1485062015 hasLocation W14850620151 @default.
- W1485062015 hasOpenAccess W1485062015 @default.
- W1485062015 hasPrimaryLocation W14850620151 @default.
- W1485062015 hasRelatedWork W1675560586 @default.
- W1485062015 hasRelatedWork W1979305135 @default.
- W1485062015 hasRelatedWork W2025476983 @default.
- W1485062015 hasRelatedWork W2111780221 @default.
- W1485062015 hasRelatedWork W2300894830 @default.
- W1485062015 hasRelatedWork W2306395728 @default.
- W1485062015 hasRelatedWork W2366431419 @default.
- W1485062015 hasRelatedWork W2382434019 @default.
- W1485062015 hasRelatedWork W2561637844 @default.
- W1485062015 hasRelatedWork W4316658607 @default.
- W1485062015 isParatext "false" @default.
- W1485062015 isRetracted "false" @default.
- W1485062015 magId "1485062015" @default.
- W1485062015 workType "book-chapter" @default.