作者
Nour Moustafa, Gideon Creech, Jill Slay
发表日期
2017/7/1
图书
Data Analytics and Decision Support for Cybersecurity
卷号
1
页码范围
127-156
出版商
Springer publishing house
简介
An intrusion detection system has become a vital mechanism to detect a wide variety of malicious activities in the cyber domain. However, this system still faces an important limitation when it comes to detecting zero-day attacks, concerning the reduction of relatively high false alarm rates. It is thus necessary to no longer consider the tasks of monitoring and analysing network data in isolation, but instead optimise their integration with decision-making methods for identifying anomalous events. This chapter presents a scalable framework for building an effective and lightweight anomaly detection system. This framework includes three modules of capturing and logging, pre-processing and a new statistical decision engine, called the Dirichlet mixture model based anomaly detection technique. The first module sniffs and collects network data while the second module analyses and filters these data to improve …
引用总数
20172018201920202021202220232024114152133434518
学术搜索中的文章