Concepedia

Publication | Closed Access

RiskRank: Security risk ranking for IP flow records

13

Citations

17

References

2010

Year

Abstract

This paper considers the monitoring of large volumes of IP flow records, typically encountered on large ISP backbone/edge routers. The approach described in our paper aims to detect relevant flow records, where relevancy is related to overall traffic activity and associated applications. The core contribution of the paper consists in a dependency graph that leverages relationships between hosts, as well as flow-specific risk modeling. The risk model is constructed using well-known link analysis algorithms and application-specific signatures.

References

YearCitations

Page 1