...
首页> 外文期刊>Security and Communications Networks >Traffic classification for managing Applications' networking profiles
【24h】

Traffic classification for managing Applications' networking profiles

机译:流量分类,用于管理应用程序的网络配置文件

获取原文
获取原文并翻译 | 示例
           

摘要

Along with the growing number of applications and end-users, online network attacks and advanced generations of malware have continuously proliferated. Many studies have addressed the issue of intrusion detection by inspecting aggregated network traffic with no knowledge of the responsible applications/services. Such systems fail to detect intrusions in applications whenever their abnormal traffic fits into the network normality profiles. We address the problem of detecting intrusions in (known) applications when their traffic exhibits anomalies. Building traffic profiles for each separate application is the main challenge of this problem. This paper surveys traffic classification methodologies, within a taxonomy framework, to find out the best possible traffic classification methodologies that could help us answer the following question: given a traffic sample, generated by a particular application, does it conforms to the expected application's traffic? The key requirements for a practical solution are discussed. Then, the referred traffic classification methodologies are assessed in terms of their capabilities, limitations and challenges for being used as a part of this solution. The approaches based on multiple sub-flows have shown the potential to be used for building robust and practical per-application profiles in near real-time. An overview of a blend of real-time approaches is also described. Copyright (c) 2016 John Wiley & Sons, Ltd.
机译:随着应用程序和最终用户数量的增加,在线网络攻击和先进的恶意软件世代相传。许多研究通过在不了解负责的应用程序/服务的情况下检查聚合的网络流量来解决入侵检测问题。每当此类应用程序的异常流量适合网络正常性配置文件时,它们就无法检测到应用程序中的入侵。我们解决了在(已知)应用程序的流量显示异常时检测入侵的问题。为每个单独的应用程序构建流量配置文件是此问题的主要挑战。本文在分类法框架内调查流量分类方法,以找出可能的最佳流量分类方法,这可以帮助我们回答以下问题:给定特定应用程序生成的流量样本,它是否符合预期应用程序的流量?讨论了实际解决方案的关键要求。然后,将根据引用的流量分类方法的功能,局限性和挑战来评估该方法,以用作此解决方案的一部分。基于多个子流的方法显示了潜在的能力,可用于近实时地构建健壮且实用的针对每个应用程序的配置文件。还概述了实时方法的混合。版权所有(c)2016 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号