Abstract
This paper deals with a new iterative Network Anomaly Detection Algorithm - NADA, which accomplishes the detection, classification and identification of traffic anomalies. NADA fully provides all information required limiting the extent of anomalies by locating them in time, by classifying them, and identifying their features as, for instance, the source and destination addresses and ports involved. To reach its goal, NADA uses a generic multi-featured algorithm executed at different time scales and at different levels of IP aggregation. Besides that, the NADA approach contributes to the definition of a set of traffic anomaly behavior-based signatures. The use of these signatures makes NADA suitable and efficient to use in a monitoring environment. © IFIP International Federation for Information Processing 2007.
Author supplied keywords
Cite
CITATION STYLE
Farraposo, S., Owezarski, P., & Monteiro, E. (2007). NADA - Network anomaly detection algorithm. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 4785 LNCS, pp. 191–194). Springer Verlag. https://doi.org/10.1007/978-3-540-75694-1_18
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.