2009 · 25 citations · 23 references
Internet Traffic AnalysisEngineeringInformation SecurityNetwork AnalysisInformation ForensicsNetwork ModelData ScienceData MiningDenial-of-service AttackMalignant Network TrafficSelf-organizing MapSocial Network AnalysisDdos DetectionIntrusion Detection SystemThreat DetectionKnowledge DiscoveryP2p Botnet TrafficComputer ScienceNetwork ScienceBusinessBotnet DetectionNetwork Traffic MeasurementModel-based Intrusion Detection
Model-based intrusion detection and knowledge discovery are combined to cluster and classify P2P botnet traffic and other malignant network activity by using a self-organizing map (som) self-trained on denied Internet firewall log entries. The SOM analyzed new firewall log entries in a case study to classify similar network activity, and discovered previously unknown local P2P bot traffic and other security issues.
23
Dorothy E. Denning · IEEE Transactions on Software Engineering · 1987 · 3.3K citations
Testing Intrusion detection systems
John McHugh · ACM Transactions on Information and System Security · 2000 · 1.3K citations · Full text
The Zombie roundup: understanding, detecting, and disrupting botnets
Evan Cooke, Farnam Jahanian, Danny McPherson · 2005 · 496 citations