本頁只刊出中文翻譯與中文說明;英文原文請見下方原文連結。
原文連結
論文資訊
- 類型:已發表論文
- 日期:2016-03-11
摘要
The rapid detection of attackers within firewalls of enterprise computer 網絡s is of paramount importance. Anomaly detectors address this problem by quantifying deviations from baseline 統計 models of normal 網絡 behavior and signaling an intrusion when the observed data deviates significantly from the baseline model. However, many anomaly detectors do not take into account plausible attacker behavior. As a result, anomaly detectors are prone to a large number of false positives due to unusual but benign activity. This paper first introduces a 隨機 model of attacker behavior which is motivated by real world attacker traversal. Then, we develop a likelihood ratio detector that compares the probability of observed 網絡 behavior under normal conditions against the case when an attacker has possibly com
※ 此為已發表論文,全文需透過期刊付費取得