arrow
Return

Slow-Paced Persistent Network Attacks Analysis and Detection Using Spectrum Analysis

delete2016-12-01
delete5
delete
OA
AI
L
Li Ming Chen *
S
Shun-Wen Hsiao
M
Meng Chang Chen
W
Wanjiun Liao
DOI:10.1109/JSYST.2014.2348567delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
A slow-paced persistent attack, such as slow worm or bot, can bewilder the detection system by slowing down their attack. Detecting such attacks based on traditional anomaly detection techniques may yield high false alarm rates. In this paper, we frame our problem as detecting slow-paced persistent attacks from a time series obtained from network trace. We focus on time series spectrum analysis to identify peculiar spectral patterns that may represent the occurrence of a persistent activity in the time domain. We propose a method to adaptively detect slow-paced persistent attacks in a time series and evaluate the proposed method by conducting experiments using both synthesized traffic and real-world traffic. The results show that the proposed method is capable of detecting slow-paced persistent attacks even in a noisy environment mixed with legitimate traffic.
Keywords:
Network security
persistent activity
slow-paced attack
spectrum analysis
time series

Journal

I
IEEE Open Journal of Circuits and Systems
IF:
2.4
Papers:
4.5K
Citations:
387

Organization

A
academia sinica - taiwan
Scholars:
1.9W
Papers: 1.6W
Citations: 17
N
National Taiwan University
Scholars:
4.7W
Papers: 4.2W
Citations: 3.6W