Differentiating network conversation flow for intrusion detection and diagnostics

James C. McEachen, John M. Zachary, D.W. Ettlich · 2004

We present a novel approach to detecting anomalous network events. Specifically, a method for characterizing and displaying the flow of conversations across a distributed system with a high number of interacting entities is discussed and analyzed. Results from simulated laboratory experiments as well as observations from operational network traffic are presented. These results suggest that our approach presents a unique perspective on anomalies in computer network traffic. Additionally, this approach produces a normal statistic that could viably be analyzed with ML/MSE estimators.

Read the paper · More papers on PaperTik