作者
Olivier Thonnard, Marc Dacier
发表日期
2008/9/1
期刊
digital investigation
卷号
5
页码范围
S128-S139
出版商
Elsevier
简介
Collecting data related to Internet threats has now become a relatively common task for security researchers and network operators. However, the huge amount of raw data can rapidly overwhelm people in charge of analyzing such data sets. Systematic analysis procedures are thus needed to extract useful information from large traffic data sets in order to assist the analyst's investigations. This work describes an analysis framework specifically developed to gain insights into honeynet data. Our forensics procedure aims at finding, within an attack data set, groups of network traces sharing various kinds of similar patterns. In our exploratory data analysis, we seek to design a flexible clustering tool that can be applied in a systematic way on different feature vectors characterizing the attacks. In this paper, we illustrate the application of our method by analyzing one specific aspect of the honeynet data, i.e. the time series …
引用总数
20082009201020112012201320142015201620172018201920202021202220232024271012461491861874211
学术搜索中的文章