Skip navigation
  •  Inicio
  • UDC 
    • Cómo depositar
    • Políticas do RUC
    • FAQ
    • Dereitos de Autor
    • Máis información en INFOguías UDC
  • Percorrer 
    • Comunidades
    • Buscar por:
    • Data de publicación
    • Autor
    • Título
    • Materia
  • Axuda
    • español
    • Gallegan
    • English
  • Acceder
  •  Galego 
    • Español
    • Galego
    • English
  
Ver ítem 
  •   RUC
  • Facultade de Informática
  • Investigación (FIC)
  • Ver ítem
  •   RUC
  • Facultade de Informática
  • Investigación (FIC)
  • Ver ítem
JavaScript is disabled for your browser. Some features of this site may not work without it.

Early Intrusion Detection for OS Scan Attacks

Thumbnail
Ver/abrir
LopezVizcaino_Manuel_2019_Early_Intrusion_Detection_for_OS_Scan_Attacks.pdf (214.4Kb)
Use este enlace para citar
http://hdl.handle.net/2183/36931
Coleccións
  • Investigación (FIC) [1685]
Metadatos
Mostrar o rexistro completo do ítem
Título
Early Intrusion Detection for OS Scan Attacks
Autor(es)
López-Vizcaíno, Manuel F.
Nóvoa, Francisco
Fernández, Diego
Carneiro, Víctor
Cacheda, Fidel
Data
2019-09
Cita bibliográfica
M. López-Vizcaíno, F. J. Novoa, D. Fernández, V. Carneiro and F. Cacheda, "Early Intrusion Detection for OS Scan Attacks," 2019 IEEE 18th International Symposium on Network Computing and Applications (NCA), Cambridge, MA, USA, 2019, pp. 1-5, doi: 10.1109/NCA.2019.8935067.
Resumo
[Abstract]: Network Intrusion Detection Systems (NIDS) are concerned with the discovery of unauthorized accesses to computer networks by analyzing the traffic in order to detect malicious activity. In the event of an intrusion, the time elapsed until the detection is a key factor to break the Cyber Kill Chain. State-of-the-art studies use a traditional evaluation based on standard accuracy metrics (e.g. precision or F-measure) without taking into account the time required to detect a threat. In this paper, we formally define the early intrusion detection problem. We perform a thorough evaluation adapting existing time-aware metrics to the early detection of threats on a computer network and we also propose a new metric (i.e. NormERDE). Our results show how a good performance on standard metrics may not correspond to good results on early detection metrics. For instance, a technique with a high level of precision could need too much time to detect a threat. Therefore, in this paper we propose taking into account time-aware metrics in NIDS evaluations due to the importance of this factor in a real world environment.
Palabras chave
Communication networks
Early intrusion detection
NIDS
 
Descrición
18th IEEE International Symposium on Network Computing and Applications, NCA 2019, Cambridge, 26 - 28 September 2019
 
This version of the article has been accepted for publication, after peer review. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works. The Version of Record is available online at: https://doi.org/10.1109/NCA.2019.8935067
 
Versión do editor
https://doi.org/10.1109/NCA.2019.8935067
Dereitos
Copyright © 2019, IEEE

Listar

Todo RUCComunidades e colecciónsPor data de publicaciónAutoresTítulosMateriasGrupo de InvestigaciónTitulaciónEsta colecciónPor data de publicaciónAutoresTítulosMateriasGrupo de InvestigaciónTitulación

A miña conta

AccederRexistro

Estatísticas

Ver Estatísticas de uso
Sherpa
OpenArchives
OAIster
Scholar Google
UNIVERSIDADE DA CORUÑA. Servizo de Biblioteca.    DSpace Software Copyright © 2002-2013 Duraspace - Suxestións