Sciweavers

IJNSEC
2008

Baseline Profile Stability for Network Anomaly Detection

14 years 17 days ago
Baseline Profile Stability for Network Anomaly Detection
Network attacks are commonplace in the Internet. One of the defense mechanisms against the network attacks is using a baseline profile established during normal operation to detect the traffic that deviates from the baseline profile. However, this approach works only if there is a stable base profile representing the legitimate network traffic. Although there has been some preliminary research, the details of profiling, such as the profile format, its size and the traffic stability by site or time, have not been widely available. In this study, we analyze actual traffic traces from two Internet traffic archives and verify the traffic stability by various aspects. The analysis shows that there are significant differences in the traffic patterns among different sites. In addition, there are some differences between different time of day or different days, even within a site, suggesting that different profiles are needed for different times. The result of this study can be used practical...
Yoohwan Kim, Ju-Yeon Jo, Kyunghee Kim Suh
Added 12 Dec 2010
Updated 12 Dec 2010
Type Journal
Year 2008
Where IJNSEC
Authors Yoohwan Kim, Ju-Yeon Jo, Kyunghee Kim Suh
Comments (0)