Matches in SemOpenAlex for { <https://semopenalex.org/work/W830742902> ?p ?o ?g. }
- W830742902 abstract "Slow and suspicious malicious activities on modern computer networks are increasingly hard to detect. An attacker may take days, weeks or months to complete an attack life cycle. A particular challenge is to monitor for stealthy attempts deliberately designed to stay beneath detection thresholds. This doctoral research presents a theoretical framework for effective monitoring of such activities. The main contribution of this work is a scalable monitoring scheme proposed in a Bayesian framework, which allows for detection of multiple attackers by setting a threshold using the Grubbs’ test. Second contribution is a tracing algorithm for such attacks. Network paths from a victim to its immediate visible hops are mapped and profiled in a Bayesian framework and the highest scored path is prioritised for monitoring. Third contribution explores an approach to minimise data collection by employing traffic sampling. The traffic is sampled using the stratification sampling technique with optimum allocation method. Using a 10% sampling rate was sufficient to detect simulated attackers, and some network parameters affected on sampling error. Final contribution is a target-centric monitoring scheme to detect nodes under attack. Target-centric approach is quicker to detect stealthy attacks and has potential to detect collusion as it completely independent from source information. Experiments are carried out in a simulated environment using the network simulator NS3. Anomalous traffic is generated along with normal traffic within and between networks using a Poisson arrival model. Our work addresses a key problem of network security monitoring: a scalable monitoring scheme for slow and suspicious activities. State size, in terms of a node score, is a small multiple of number of nodes in the network and hence storage is feasible for very large scale networks. Effective monitoring of slow suspicious activities on computer networks Harsha Kumara Kalutarage Digital Security & Forensics (SaFe) Research Group Department of Computing, Faculty of Engineering & Computing Coventry University, UK A thesis submitted in partial fulfilment of the requirements for the Degree of Doctor of Philosophy in Cyber Security Date: November 15, 2013" @default.
- W830742902 created "2016-06-24" @default.
- W830742902 creator A5005926383 @default.
- W830742902 date "2013-01-01" @default.
- W830742902 modified "2023-09-26" @default.
- W830742902 title "Effective monitoring of slow suspicious activites on computer networks" @default.
- W830742902 cites W1484917059 @default.
- W830742902 cites W1486402922 @default.
- W830742902 cites W1496450597 @default.
- W830742902 cites W1496859626 @default.
- W830742902 cites W1547255972 @default.
- W830742902 cites W1559384589 @default.
- W830742902 cites W1570968621 @default.
- W830742902 cites W1572811218 @default.
- W830742902 cites W1575210522 @default.
- W830742902 cites W1576273331 @default.
- W830742902 cites W1583975142 @default.
- W830742902 cites W1591763911 @default.
- W830742902 cites W1594990268 @default.
- W830742902 cites W1627091850 @default.
- W830742902 cites W170020907 @default.
- W830742902 cites W1729765288 @default.
- W830742902 cites W1763270762 @default.
- W830742902 cites W1952056635 @default.
- W830742902 cites W1967228187 @default.
- W830742902 cites W1970814655 @default.
- W830742902 cites W1974918169 @default.
- W830742902 cites W1978239142 @default.
- W830742902 cites W1988897678 @default.
- W830742902 cites W1994894547 @default.
- W830742902 cites W200399331 @default.
- W830742902 cites W2005811057 @default.
- W830742902 cites W2007087405 @default.
- W830742902 cites W2008155663 @default.
- W830742902 cites W2010729689 @default.
- W830742902 cites W2011787683 @default.
- W830742902 cites W2021767337 @default.
- W830742902 cites W2031163547 @default.
- W830742902 cites W2034171445 @default.
- W830742902 cites W2035602559 @default.
- W830742902 cites W2038104327 @default.
- W830742902 cites W2045414949 @default.
- W830742902 cites W2049446512 @default.
- W830742902 cites W2049652236 @default.
- W830742902 cites W2053003065 @default.
- W830742902 cites W2053237536 @default.
- W830742902 cites W2060450695 @default.
- W830742902 cites W206164581 @default.
- W830742902 cites W2065523140 @default.
- W830742902 cites W2067361528 @default.
- W830742902 cites W2070535792 @default.
- W830742902 cites W2076087677 @default.
- W830742902 cites W2094718768 @default.
- W830742902 cites W2095575865 @default.
- W830742902 cites W2095979141 @default.
- W830742902 cites W2096030967 @default.
- W830742902 cites W2096318715 @default.
- W830742902 cites W2097980166 @default.
- W830742902 cites W2104125350 @default.
- W830742902 cites W2106061258 @default.
- W830742902 cites W2108673751 @default.
- W830742902 cites W2109121608 @default.
- W830742902 cites W2110878833 @default.
- W830742902 cites W2113448226 @default.
- W830742902 cites W2113997717 @default.
- W830742902 cites W2117222554 @default.
- W830742902 cites W2117747231 @default.
- W830742902 cites W2122170585 @default.
- W830742902 cites W2122646361 @default.
- W830742902 cites W2124430127 @default.
- W830742902 cites W2124850309 @default.
- W830742902 cites W2126276672 @default.
- W830742902 cites W2126455177 @default.
- W830742902 cites W2128023014 @default.
- W830742902 cites W2130673717 @default.
- W830742902 cites W2143439191 @default.
- W830742902 cites W2150847526 @default.
- W830742902 cites W2151156661 @default.
- W830742902 cites W2155162297 @default.
- W830742902 cites W2155398148 @default.
- W830742902 cites W2158449659 @default.
- W830742902 cites W2161565143 @default.
- W830742902 cites W2162774438 @default.
- W830742902 cites W2165032725 @default.
- W830742902 cites W2169455789 @default.
- W830742902 cites W2170210941 @default.
- W830742902 cites W2170335877 @default.
- W830742902 cites W2170404483 @default.
- W830742902 cites W2170771030 @default.
- W830742902 cites W2171410433 @default.
- W830742902 cites W2171874047 @default.
- W830742902 cites W2183681512 @default.
- W830742902 cites W2185548957 @default.
- W830742902 cites W2262045390 @default.
- W830742902 cites W2319038039 @default.
- W830742902 cites W245216966 @default.
- W830742902 cites W2461227904 @default.
- W830742902 cites W2534766289 @default.
- W830742902 cites W2582743722 @default.
- W830742902 cites W2587262467 @default.