AUTOMATIC VALIDATION AND EVIDENCE COLLECTION OF SECURITY RELATED NETWORK ANOMALIES

Ignasi Paredes-Oliva, Pere Barlet‐Ros, Maurizio Molina · 2009

DANTE has recently benchmarked and deployed several commercial tools for anomaly detection based on Sampled NetFlow. According to this experience, the number of false positives (even in commercial tools) is still significant (in the order of 10-20% even for the best performing ones). Therefore, human mediation is still fundamental before taking actions to mitigate and prevent recurrence of security related anomalies, especially if this involves the cooperation of a neighbouring network. Currently, this anomaly validation process mainly relies on security engineers’ skills.

Read the paper · More papers on PaperTik