作者: Milan Čermák , Pavel Čeleda , Jan Vykopal
DOI: 10.1007/978-3-319-13488-8_20
关键词: Internet communication 、 Computer network 、 Campus network 、 Ip address 、 Anomaly detection 、 Large networks 、 Engineering 、 Flow metering 、 Domain Name System
摘要: Almost every Internet communication is preceded by a translation of DNS name to an IP address. Therefore monitoring traffic can effectively extend capabilities current methods for network anomaly detection. In order monitor this traffic, we propose new flow metering algorithm that saves resources exporter. Next, show benefits the detection, introduce novel detection using extended flows. The evaluation these shows our approach not only reveals anomalies but also scales well in campus network.