Matches in SemOpenAlex for { <https://semopenalex.org/work/W2407971567> ?p ?o ?g. }
Showing items 1 to 73 of
73
with 100 items per page.
- W2407971567 abstract "As the Internet continues to grow in size and complexity, the challenge of effectively provisioning, managing, and securing it has become inextricably linked to a deep understanding of Internet traffic. Due to vast amount of data, and wide diversity of end-hosts and services found in Internet traffic, we need techniques that can extract underlying structures and significant communication patterns. In this dissertation, we propose a systematic methodology for profiling Internet backbone traffic that (1) not only automatically discovers significant behaviors (communication patterns) of interest from massive traffic data, (2) but also provides a plausible interpretation of these behaviors to aid security analysts in understanding and quickly identifying anomalous events of significance. For these purposes, a combination of data mining and information-theoretic techniques are employed to automatically cull useful information from largely unstructured data. An entropy-based adaptive algorithm is developed to extract significant clusters of interest. We introduce a behavior classification scheme that automatically groups clusters into classes based on communication patterns and feature distributions using relative uncertainty. In addition, we use dominant state analysis to uncover cluster structure for interpretive analyses. The analysis of traffic data collected from a variety of links at a large IP backbone network shows that the approach indeed provides a robust and meaningful way of characterizing and interpreting network behavior. Given unwanted traffic revealed in exploit behavior profiles, we develop simple yet effective blocking strategies an IP network may pursue to reduce substantial exploit traffic. To demonstrate the operational feasibility, a real-time traffic profiling system has been designed and implemented. Experiment results show that under normal traffic conditions, resources on a commodity PC are sufficient to continuously process flow records and build behavior profiles for high-speed links in operational networks. For sudden traffic surges caused by events such as denial of service attacks or worm outbreaks, a novel profiling aware filtering algorithm is proposed to reduce the CPU and memory cost of the real-time system while maintaining high profiling accuracy. Thus, the profiling system can become an effective tool for security analysts with applications to critical problems such as detecting unknown security exploits and profiling unwanted traffic." @default.
- W2407971567 created "2016-06-24" @default.
- W2407971567 creator A5011264725 @default.
- W2407971567 creator A5049423626 @default.
- W2407971567 date "2006-01-01" @default.
- W2407971567 modified "2023-09-24" @default.
- W2407971567 title "Enhancing security in an ip backbone network" @default.
- W2407971567 hasPublicationYear "2006" @default.
- W2407971567 type Work @default.
- W2407971567 sameAs 2407971567 @default.
- W2407971567 citedByCount "0" @default.
- W2407971567 crossrefType "journal-article" @default.
- W2407971567 hasAuthorship W2407971567A5011264725 @default.
- W2407971567 hasAuthorship W2407971567A5049423626 @default.
- W2407971567 hasConcept C110875604 @default.
- W2407971567 hasConcept C111919701 @default.
- W2407971567 hasConcept C120314980 @default.
- W2407971567 hasConcept C124101348 @default.
- W2407971567 hasConcept C136764020 @default.
- W2407971567 hasConcept C165696696 @default.
- W2407971567 hasConcept C172191483 @default.
- W2407971567 hasConcept C187191949 @default.
- W2407971567 hasConcept C2522767166 @default.
- W2407971567 hasConcept C2781317605 @default.
- W2407971567 hasConcept C31258907 @default.
- W2407971567 hasConcept C38652104 @default.
- W2407971567 hasConcept C41008148 @default.
- W2407971567 hasConcept C51274741 @default.
- W2407971567 hasConcept C63969886 @default.
- W2407971567 hasConcept C88796919 @default.
- W2407971567 hasConceptScore W2407971567C110875604 @default.
- W2407971567 hasConceptScore W2407971567C111919701 @default.
- W2407971567 hasConceptScore W2407971567C120314980 @default.
- W2407971567 hasConceptScore W2407971567C124101348 @default.
- W2407971567 hasConceptScore W2407971567C136764020 @default.
- W2407971567 hasConceptScore W2407971567C165696696 @default.
- W2407971567 hasConceptScore W2407971567C172191483 @default.
- W2407971567 hasConceptScore W2407971567C187191949 @default.
- W2407971567 hasConceptScore W2407971567C2522767166 @default.
- W2407971567 hasConceptScore W2407971567C2781317605 @default.
- W2407971567 hasConceptScore W2407971567C31258907 @default.
- W2407971567 hasConceptScore W2407971567C38652104 @default.
- W2407971567 hasConceptScore W2407971567C41008148 @default.
- W2407971567 hasConceptScore W2407971567C51274741 @default.
- W2407971567 hasConceptScore W2407971567C63969886 @default.
- W2407971567 hasConceptScore W2407971567C88796919 @default.
- W2407971567 hasLocation W24079715671 @default.
- W2407971567 hasOpenAccess W2407971567 @default.
- W2407971567 hasPrimaryLocation W24079715671 @default.
- W2407971567 hasRelatedWork W1490857559 @default.
- W2407971567 hasRelatedWork W1771701887 @default.
- W2407971567 hasRelatedWork W1965559657 @default.
- W2407971567 hasRelatedWork W1988182815 @default.
- W2407971567 hasRelatedWork W2009255782 @default.
- W2407971567 hasRelatedWork W2024254884 @default.
- W2407971567 hasRelatedWork W2098366185 @default.
- W2407971567 hasRelatedWork W2118983374 @default.
- W2407971567 hasRelatedWork W2148346742 @default.
- W2407971567 hasRelatedWork W2149469122 @default.
- W2407971567 hasRelatedWork W2175388903 @default.
- W2407971567 hasRelatedWork W2223979599 @default.
- W2407971567 hasRelatedWork W2408790947 @default.
- W2407971567 hasRelatedWork W2600762561 @default.
- W2407971567 hasRelatedWork W2787465507 @default.
- W2407971567 hasRelatedWork W2898772172 @default.
- W2407971567 hasRelatedWork W2961066337 @default.
- W2407971567 hasRelatedWork W2969449541 @default.
- W2407971567 hasRelatedWork W3117767516 @default.
- W2407971567 hasRelatedWork W68363329 @default.
- W2407971567 isParatext "false" @default.
- W2407971567 isRetracted "false" @default.
- W2407971567 magId "2407971567" @default.
- W2407971567 workType "article" @default.