Effective network security monitoring: from attribution to target-centric monitoring


Autoria(s): Shaikh, Siraj Ahmed; Kalutarage, Harsha Kumara
Data(s)

01/05/2016

Resumo

<p>Network security monitoring remains a challenge. As global networks scale up, in terms of traffic, volume and speed, effective attribution of cyber attacks is increasingly difficult. The problem is compounded by a combination of other factors, including the architecture of the Internet, multi-stage attacks and increasing volumes of nonproductive traffic. This paper proposes to shift the focus of security monitoring from the source to the target. Simply put, resources devoted to detection and attribution should be redeployed to efficiently monitor for targeting and prevention of attacks. The effort of detection should aim to determine whether a node is under attack, and if so, effectively prevent the attack. This paper contributes by systematically reviewing the structural, operational and legal reasons underlying this argument, and presents empirical evidence to support a shift away from attribution to favour of a target-centric monitoring approach. A carefully deployed set of experiments are presented and a detailed analysis of the results is achieved.</p>

Identificador

http://pure.qub.ac.uk/portal/en/publications/effective-network-security-monitoring-from-attribution-to-targetcentric-monitoring(8298ebc6-bb6c-4e89-9c12-d73a47fd29bf).html

http://dx.doi.org/10.1007/s11235-015-0071-0

http://www.scopus.com/inward/record.url?scp=84930532013&partnerID=8YFLogxK

Idioma(s)

eng

Direitos

info:eu-repo/semantics/closedAccess

Fonte

Shaikh , S A & Kalutarage , H K 2016 , ' Effective network security monitoring: from attribution to target-centric monitoring ' Telecommunication Systems , vol 62 , no. 1 , pp. 167-178 . DOI: 10.1007/s11235-015-0071-0

Palavras-Chave #Attribution #Bayesian statistics #Communication networks #Network security #Scalable monitoring #/dk/atira/pure/subjectarea/asjc/2200/2208 #Electrical and Electronic Engineering
Tipo

article