White Papers

Attribution and Aggregation of Network Flows for Security Analysis

Category: Security

Tags: infrastructure, network

Overview This paper describes a network flow analyzer that is capable of attribution and aggregation of different flows into single activity events for the purposes of identifying suspicious and illegitimate behaviors. Flows are correlated with security events using the Process Query System (PQS) infrastructure. This paper shows results from initial experiments and describes plans for extending the effort. The correlation of networks flows with security events appears to have high potential for aggregating disparate network and host activity and for classifying network activity as either benign or suspicious.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Dartmouth College
File Format
PDF
Date Published
May 21, 2008
Format
White Papers
Topics
Network Security, Security Tools, Security Management

Similiar White Papers

Anonymous Proxy: A Growing Trend in Internet Abuse

Anonymous Proxy: A Growing Trend in Internet Abuse

Anonymous proxies are an unseen threat--a student's or employee's backdoor to malicious or productivity-sapping sites on

Publisher: Bloxx  |  Tags: database, third-generation, trend

Balancing Security Against Productivity

Balancing Security Against Productivity

What makes for great security? Is it about keeping the bad guys out or letting the good guys in? About defending atta

Publisher: Novell  |  Tags: management, security management

Social Networking: Brave New World or Revolution from Hell? A look at the phenomenon of Social Networking and the implications for Businesses

Social Networking: Brave New World or Revolution from Hell? A look at the phenomenon of Social Networking and the implications for Businesses

According to recent surveys, employee social networking is growing rapidly, on hot sites such as Facebook, LinkedIn and

Publisher: MessageLabs, now part of Symantec  |  Tags: enterprise security, social networking

A More Secure Front Door: Enterprise Single Sign-on and Strong Authentication

A More Secure Front Door: Enterprise Single Sign-on and Strong Authentication

In recent years, enterprise single sign-on (ESSO) has emerged as an easy, smart, and affordable way for organizations of

Publisher: Imprivata  |  Tags: authentication, biometrics, passwords, productivity

Information Security Metrics: Using McAfee Foundstone FoundScore to assign metrics and measure enterprise risk

Information Security Metrics: Using McAfee Foundstone FoundScore to assign metrics and measure enterprise risk

This white paper explores the use of reliable metrics to measure the business value of expenditures and actions taken re

Publisher: McAfee  |  Tags: information security, tco

Dartmouth College White Papers

Project Management Methodology in Human Resource Management

Project Management Methodology in Human Resource Management

The concept of project management methodology can be leveraged to add value to an institution's strategic initiatives. T

Publisher: Dartmouth College  |  Tags: hr, management, project management

Hierarchical Power-Aware Routing in Sensor Networks

Hierarchical Power-Aware Routing in Sensor Networks

This paper discusses online power-aware routing in large sensor networks. The authors seek to optimize the lifetime of t

Publisher: Dartmouth College  |  Tags: computing, digital, network

Predictability of WLAN Mobility and Its Effects on Bandwidth Provisioning

Predictability of WLAN Mobility and Its Effects on Bandwidth Provisioning

Wireless Local Area Networks (WLANs) are emerging as a popular technology for access to the Internet and enterprise netw

Publisher: Dartmouth College  |  Tags: data, mobile network, mobility, network

AutoPKI: A PKI Resources Discovery System?

AutoPKI: A PKI Resources Discovery System?

The central goal of Public Key Infrastructure (PKI) is to enable trust judgments between distributed users. Although cer

Publisher: Dartmouth College  |  Tags: data, pki

Group-Aware Stream Filtering for Bandwidth-Efficient Data Dissemination

Group-Aware Stream Filtering for Bandwidth-Efficient Data Dissemination

This paper is concerned with disseminating high-volume data streams to many simultaneous applications over a low-bandwid

Publisher: Dartmouth College  |  Tags: applications, data, network