دانلود مقاله ISI انگلیسی شماره 76914
ترجمه فارسی عنوان مقاله

تجزیه و تحلیل ترافیک امنیتی اکتشافی برای تشخیص ناهنجاری

عنوان انگلیسی
Exploratory security analytics for anomaly detection
کد مقاله سال انتشار تعداد صفحات مقاله انگلیسی
76914 2016 22 صفحه PDF
منبع

Publisher : Elsevier - Science Direct (الزویر - ساینس دایرکت)

Journal : Computers & Security, Volume 56, February 2016, Pages 28–49

ترجمه کلمات کلیدی
تجزیه و تحلیل ترافیک امنیتی؛ هشدار شبکه؛ خصوصیات زمانی؛ تجزیه و تحلیل سری های زمانی - تشخیص ناهنجاری
کلمات کلیدی انگلیسی
Security analytics; Network alerts; Temporal characterization; Time series analysis; Anomaly detection

چکیده انگلیسی

The huge number of alerts generated by network-based defense systems prevents detailed manual inspections of security events. Existing proposals for automatic alerts analysis work well in relatively stable and homogeneous environments, but in modern networks, that are characterized by extremely complex and dynamic behaviors, understanding which approaches can be effective requires exploratory data analysis and descriptive modeling. We propose a novel framework for automatically investigating temporal trends and patterns of security alerts with the goal of understanding whether and which anomaly detection approaches can be adopted for identifying relevant security events. Several examples referring to a real large network show that, despite the high intrinsic dynamism of the system, the proposed framework is able to extract relevant descriptive statistics that allow to determine the effectiveness of popular anomaly detection approaches on different alerts groups.