On the use of co-occurrence matrices for network anomaly detection
Christian Callegari, Stefano Giordano, Michele Pagano · 2009
In the last few years the number and impact of security attacks over the Internet have been continuously increasing. Since it is impossible to guarantee complete protection to a system by means of the "classical" prevention mechanisms, the use of Intrusion Detection Systems (IDSs) has emerged as a key element in network security. In this paper we address the problem considering some techniques for detecting network anomalies, based on the use of co-occurrence matrices, to model the "normal" behavior of the TCP connections.