FREE Registration is required
Overview:
This paper describes a network flow analyzer that is capable of attribution and aggregation of different flows into single activity events for the purposes of identifying suspicious and illegitimate behaviors. Flows are correlated with security events using the Process Query System (PQS) infrastructure. This paper shows results from initial experiments and describes plans for extending the effort. The correlation of networks flows with security events appears to have high potential for aggregating disparate network and host activity and for classifying network activity as either benign or suspicious.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Size: | 54 KB | |
| Date: | Jan 2008 | ||
| Pages: | 4 |
People who downloaded this item also downloaded
White Papers, Webcasts, and Resources
- Riverbed's "Jack" Product Demo: The Most Complete WAN Acceleration Solution RiverbedHave WAN acceleration solutions got your head spinning? Watch a day in the life of Jack, the IT Guy as he sorts it all out...
- Live Webcast: Saving 70% with Google Apps over Microsoft Exchange with Mattson Technology GoogleHear how a global technology company transformed the way it does business--and turned off 6 of its servers--simply by switching to Google Apps.
- Is Your Security Effective? The Value of Application Security Testing Tools Ounce LabsDiscover why you need strong application security testing tools, what these tools should include, and how to select the best solution for your needs.
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- SmartPlanet
Discover innovative insight and ideas that impact the world around you -
SmartPlanet offers expert advice on innovations in healthcare, including electronic personal health records, treatment, privacy and regulation, and the green technologies that make it happen.
- Learn more >>
Featured Training Courses
Enterprise Applications
- Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
- New Online Dashboard
- Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline






