Attack detection in large networks
J. May, John C. Peterson, John Bauman · 2002
Attacks on large networks are detected using their inherent statistical characteristics. Emphasis is on detecting attacks on the network instead of attacks on computers attached to the network. Denial-of-Service (DoS) attacks and attacks on network components such as routers are detected. A high-speed self-organizing system TCP/IP network simulation was developed to implement DoS attacks. N-gram algorithms were developed to detect anomalous operation of individual network nodes. Plans for algorithm development and testing on a large real network are presented.