redAlert: Data-mining and visualisation for IP data analysis

被引:0
|
作者
Kirkham, EA [1 ]
Botham, CP [1 ]
机构
[1] BT Adastral Pk, Ipswich IP5 3RE, Suffolk, England
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Security of modem multi-service IP networks has become central to company profitability and success. In this context, automated intrusion detection remains crucially important for detecting malicious activity and potential attacks. This paper focuses on redAlert, a data-mining/statistical tool where the fundamental idea is to recognise intrusion attempts by observing changes in behaviour associated with particular IP addresses. The art of the technique is to adequately characterise behaviours and so sort each IP address into a cluster, then look for uncommon changes from one cluster to another, referred to as rare events. In performance evaluation, redAlert successfully identified IP addresses responsible for rare events, demonstrating that data-mining has good potential for IP intrusion detection.
引用
收藏
页码:24 / 30
页数:7
相关论文
共 50 条
  • [1] Data quality analysis using data-mining methods
    Windheuser, U
    [J]. OPERATIONS RESEARCH PROCEEDINGS 1999, 2000, : 304 - 310
  • [2] Clinical Data-Mining
    Guzzetta, Charles
    [J]. JOURNAL OF TEACHING IN SOCIAL WORK, 2010, 30 (03) : 353 - 355
  • [3] Clinical Data-Mining
    Joelson, Richard B.
    [J]. SOCIAL WORK IN MENTAL HEALTH, 2010, 9 (01) : 71 - 72
  • [4] DATA-MINING DYNAMITE
    KRIVDA, CD
    [J]. BYTE, 1995, 20 (10): : 97 - &
  • [5] Building a data-mining grid for multiple human brain data analysis
    Zhong, N
    Hu, J
    Motomura, S
    Wu, JL
    Liu, CN
    [J]. COMPUTATIONAL INTELLIGENCE, 2005, 21 (02) : 177 - 196
  • [6] DATA-MINING CHESS DATABASES
    Bleicher, E.
    Haworth, G. Mc C.
    van der Heijden, H. M. J. F.
    [J]. ICGA JOURNAL, 2010, 33 (04) : 212 - 214
  • [7] Data-mining behavioural data from the web
    Balogh, Zoltan
    [J]. PROCEEDINGS OF 2016 10TH INTERNATIONAL CONFERENCE ON SOFTWARE, KNOWLEDGE, INFORMATION MANAGEMENT & APPLICATIONS (SKIMA), 2016, : 122 - 127
  • [8] Data-mining application architecture
    Petersohn, H
    [J]. WIRTSCHAFTSINFORMATIK, 2004, 46 (01): : 15 - 21
  • [9] Data-mining the past environment
    Theron, R
    Paillard, D
    Cortijo, E
    Flores, JA
    Vaquero, M
    Sierro, FJ
    Waelbroeck, C
    [J]. IGARSS 2003: IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM, VOLS I - VII, PROCEEDINGS: LEARNING FROM EARTH'S SHAPES AND SIZES, 2003, : 3688 - 3690
  • [10] A DATA-MINING BASED METHOD FOR THE GAIT PATTERN ANALYSIS
    Rudek, Marcelo
    Silva, Nicoli Maria
    Steinmetz, Jean-Paul
    Jahnen, Andreas
    [J]. FACTA UNIVERSITATIS-SERIES MECHANICAL ENGINEERING, 2015, 13 (03) : 205 - 215