Title :
Real-Time Representation of Network Traffic Behavior for Enhanced Security
Author :
McEachen, John C. ; Zachary, John M.
Author_Institution :
Dept. of Electr. & Comput. Eng., Naval Postgraduate Sch., Monterey, CA
Abstract :
This paper presents a model for real-time network monitoring and anomaly detection that provides a holistic view of network conversation exchanges. We argue that monitoring and anomaly detection are necessary mechanisms for ensuring secure and dependable network computing infrastructure. The model for network traffic exchange is based on a modified Ehrenfest urn model and combines statistical physics and queuing theory to provide macrostate descriptions of complex networked systems when the exact microstate parameters of each element in the system precludes global understanding from first principles. The conversation exchange dynamics model for real-time network monitoring and anomaly detection is formally presented in this context as a system-driven data reduction model. The model induces a unique real-time visualization capability for network monitoring and detection of anomalous events. An implementation of the model and visualization capability is presented along with laboratory tests and successful detection of computer network attacks
Keywords :
computer network management; queueing theory; real-time systems; security of data; anomaly detection; computer network attacks; modified Ehrenfest urn model; network traffic; queuing theory; real-time network monitoring; real-time visualization; security; statistical physics; system-driven data reduction model; Computer networks; Computerized monitoring; Context modeling; Data visualization; Event detection; Physics; Queueing analysis; Real time systems; Telecommunication traffic; Traffic control; Intrusion detection; network diagnostics; statistical mechanics;
Conference_Titel :
Information Technology and Applications, 2005. ICITA 2005. Third International Conference on
Conference_Location :
Sydney, NSW
Print_ISBN :
0-7695-2316-1
DOI :
10.1109/ICITA.2005.230