White Papers

Detection of Slow Malicious Worms Using Multi-Sensor Data Fusion

Category: Security

Tags: data

Overview Detection of slow worms is particularly challenging due to the stealthy nature of their propagation techniques and their ability to blend with normal traffic patterns. This paper, proposes a distributed detection approach based on the Generalized Evidence Processing (GEP) theory, a sensor integration and data fusion technique. With GEP theory, evidence collected by distributed detectors determines the probability associated with a detection decision under a hypothesis. The collected evidence is combined to arrive at an optimal fused detection decision by minimizing a cumulative decision risk function. Typically, malicious traffic flows of varying scanning rates can occur in the wild, and the difficulty in detecting slow scanning worms in particular can be exacerbated by interference from other traffic flows scanning at faster rates.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Carleton University
File Format
PDF
Date Published
Jun 20, 2009
Format
White Papers
Topics
Intrusion Detection Systems, Network Security

Similiar White Papers

Intrusion detection checklist: Six stages of handling attacks

Intrusion detection checklist: Six stages of handling attacks

Equipping your organization to deal with system intrusions requires a many-faceted approach. This checklist is designed

Publisher: TechRepublic  |  Tags: data, html

Secure your network with Snort intrusion prevention techniques

Secure your network with Snort intrusion prevention techniques

This sample chapter, taken from Sams' Intrusion Detection with Snort, discusses some advanced concepts in using S

Publisher: TechRepublic  |  Tags: applications, network

A Brief History of Network Security and the Need for Host Based Intrusion Detection

A Brief History of Network Security and the Need for Host Based Intrusion Detection

This paper describes the present state of information and network security with specific concentration on Host-based Int

Publisher: Tetrad Digital Integrity (TDI)  |  Tags: network, network security

A Neural Network Based System for Intrusion Detection and Classification of Attacks

A Neural Network Based System for Intrusion Detection and Classification of Attacks

With the rapid expansion of computer networks during the past decade, security has become a crucial issue for computer s

Publisher: Queen's University  |  Tags: network

Data Mining and Machine Learning - Towards Reducing False Positives in Intrusion Detection

Data Mining and Machine Learning - Towards Reducing False Positives in Intrusion Detection

Intrusion Detection Systems (IDSs) are used to monitor computer systems for signs of security violations. Having detecte

Publisher: IBM  |  Tags: data, data mining, false positives

Carleton University White Papers

Competition in the Canadian Mobile Wireless Telecommunications Industry

Competition in the Canadian Mobile Wireless Telecommunications Industry

The purpose of this paper is to examine several issues arising from the report of the Telecommunications Policy Review P

Publisher: Carleton University  |  Tags: mobile wireless

Strategies for Fast Scanning and Handovers in WiMax/802.16

Strategies for Fast Scanning and Handovers in WiMax/802.16

In WiMax/IEEE 802.16 with mobility support, scanning for an available channel by a mobile station, at start up or when a

Publisher: Carleton University  |  Tags: data, mobility, network, wimax

Local Authentication in WiMAX

Local Authentication in WiMAX

The IEEE 802.16 standard Privacy and Key Management (PKM) protocol suffers from a number of performance and security con

Publisher: Carleton University  |  Tags: authentication, network

User Controlled Lightpath Management System Based on a Service Oriented Architecture

User Controlled Lightpath Management System Based on a Service Oriented Architecture

This paper describes a User Controlled Lightpath provisioning and configuration management system. The system allows use

Publisher: Carleton University  |  Tags: management, network

Rogue-Base Station Detection in WiMax/802.16 Wireless Access Networks

Rogue-Base Station Detection in WiMax/802.16 Wireless Access Networks

This paper addresses to problem of detecting a rogue Base Station (BS) in WiMax/802.16 wireless access networks. A rogue

Publisher: Carleton University  |  Tags: network, wimax, wireless networks