作者: Philip K. Chan , Rachna Vargiya
DOI:
关键词:
摘要: Most of the current anomaly detection methods for network traffic rely on packet header studying behavior. We believe that significant information lies in payload and hence it is important to model as well. Since many protocols exist new are frequently introduced, parsing based protocol specification time-consuming. Instead relying specification, we propose four different characteristics streams bytes, which can help us develop algorithms into tokens. feed extracted tokens from algorithm. Our empirical results indicated our techniques extract improve rate.