Publication Details
ASNM: Advanced Security Network Metrics for Attack Vector Description
Barabas Maroš, Ing., Ph.D.
Chmelař Petr, Ing.
Drozd Michal, Ing.
Hanáček Petr, doc. Dr. Ing. (DITS)
behavioral signature, detection, IDS, network metrics, security
The main goal of this paper was to present formal description of metrics extraction process with respect to a communication context. Then there was defined the set of metrics included in the final behavioral signature. Second part of the paper describes experiments performed with the state-of-the-art set of network metrics designed by A. Moore, which were compared to our proposed experimental set.
There is considerable interest in developing novel detection methods based on new metrics for description of network flow to identify connection characteristics, for instance to permit early identification of emerging security incidents, rapid detection of infections within internal networks, or instantaneous prevention of forming attacks. In this paper we propose a method for extraction data from network flow and contextual separation of partial connections using set of network metrics that create a signature defining the connection behavior. We begin with definition of input dataset of captured communication and the process of extraction metrics from separated connections. Then we define the set of metrics included in the final behavioral signature. Second part of the article describes experiments performed with the state-of-the-art set of network metrics with comparison to our proposed experimental set. The paper is concluded with the experiment results.
@inproceedings{BUT103452,
author="Ivan {Homoliak} and Maroš {Barabas} and Petr {Chmelař} and Michal {Drozd} and Petr {Hanáček}",
title="ASNM: Advanced Security Network Metrics for Attack Vector Description",
booktitle="Proceedings of the 2013 International Conference on Security & Management",
year="2013",
pages="350--358",
publisher="Computer Science Research, Education, and Applications Press",
address="Las Vegas",
isbn="1-60132-259-3",
url="https://www.fit.vut.cz/research/publication/10248/"
}