2012 IntrusionAsantisocialCommunicat
- (Ding et al., 2012) ⇒ Qi Ding, Natallia Katenka, Paul Barford, Eric Kolaczyk, and Mark Crovella. (2012). “Intrusion As (anti)social Communication: Characterization and Detection.” In: Proceedings of the 18th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD-2012). ISBN:978-1-4503-1462-6 doi:10.1145/2339530.2339670
Subject Headings:
Notes
Cited By
- http://scholar.google.com/scholar?q=%222012%22+Intrusion+As+%28anti%29social+Communication%3A+Characterization+and+Detection
- http://dl.acm.org/citation.cfm?id=2339530.2339670&preflayout=flat#citedby
Quotes
Author Keywords
Abstract
A reasonable definition of intrusion is: entering a community to which one does not belong. This suggests that in a network, intrusion attempts may be detected by looking for communication that does not respect community boundaries. In this paper, we examine the utility of this concept for identifying malicious network sources. In particular, our goal is to explore whether this concept allows a core-network operator using flow data to augment signature-based systems located at network edges. We show that simple measures of communities can be defined for flow data that allow a remarkably effective level of intrusion detection simply by looking for flows that do not respect those communities. We validate our approach using labeled intrusion attempt data collected at a large number of edge networks. Our results suggest that community-based methods can offer an important additional dimension for intrusion detection systems.
References
;
Author | volume | Date Value | title | type | journal | titleUrl | doi | note | year | |
---|---|---|---|---|---|---|---|---|---|---|
2012 IntrusionAsantisocialCommunicat | Mark Crovella Qi Ding Natallia Katenka Paul Barford Eric Kolaczyk | Intrusion As (anti)social Communication: Characterization and Detection | 10.1145/2339530.2339670 | 2012 |