Check out the new USENIX Web site. next up previous
Next: Performance Up: Supported Analyses Previous: Historical trend analyses


Event-driven analyses

Real-time alert data published by alert repositories offers compelling value as a source of early warning signs that a new outbreak of malicious activity is emerging across the contributor pool. The focus of this analysis is to identify significant changes or sudden inflections in alert production that may be indicative of a currently occurring attack.

A more challenging task is to identify propagation patterns in the occurrence of event_IDs and volumes, which is necessary to analyze spreading behavior of Internet-scale intrusion activity. Both hashing and keyed hashing destroy all topological information in IP addresses, making it infeasible to determine whether two sanitized alerts belong to the same region of address space. A possible solution may be offered by prefix-preserving anonymization [36], but we leave these techniques for future investigation.


next up previous
Next: Performance Up: Supported Analyses Previous: Historical trend analyses
Vitaly Shmatikov 2004-05-18