DocumentCode :
66228
Title :
A global-local approach for estimating the Internet´s threat level
Author :
Kollias, Spyridon ; Vlachos, V. ; Papanikolaou, A. ; Chatzimisios, Periklis ; Ilioudis, Christos ; Metaxiotis, Kostas
Author_Institution :
Dept. of Inf., Univ. of Piraeus, Piraeus, Greece
Volume :
16
Issue :
4
fYear :
2014
fDate :
Aug. 2014
Firstpage :
407
Lastpage :
414
Abstract :
The Internet is a highly distributed and complex system consisting of billion devices and has become the field of various kinds of conflicts during the last two decades. As a matter of fact, various actors utilise the Internet for illicit purposes, such as for performing distributed denial of service attacks (DDoS) and for spreading various types of aggressive malware. Despite the fact that numerous services provide information regarding the threat level of the Internet, they are mostly based on information acquired by their sensors or on offline statistical sampling of various security applications (antivirus software, intrusion detection systems, etc.). This paper introduces proactive threat observatory system (PROTOS), an open-source early warning system that does not require a commercial license and is capable of estimating the threat level across the Internet. The proposed system utilises both a global and a local approach, and is thus able to determine whether a specific host is under an imminent threat, as well as to provide an estimation of the malicious activity across the Internet. Apart from these obvious advantages, PROTOS supports a large-scale installation and can be extended even further to improve the effectiveness by incorporating prediction and forecasting techniques.
Keywords :
Internet; computer network security; computer viruses; public domain software; DDoS; Internet threat level estimation; PROTOS; distributed denial-of-service attacks; distributed-complex system; forecasting technique; global-local approach; large-scale installation; malicious activity estimation; malware; open-source early warning system; prediction technique; proactive threat observatory system; Computer architecture; Databases; Internet; Security; Sensor systems; Servers; Computer virus; forecasting; intrusion detection; security; time series;
fLanguage :
English
Journal_Title :
Communications and Networks, Journal of
Publisher :
ieee
ISSN :
1229-2370
Type :
jour
DOI :
10.1109/JCN.2014.000070
Filename :
6896564
Link To Document :
بازگشت