MULAN: Multi-Level Adaptive Network filter

3Citations
Citations of this article
5Readers
Mendeley users who have this article in their library.
Get full text

Abstract

A security engine should detect network traffic attacks at line-speed. When an attack is detected, a good security engine should screen away the offending packets and continue to forward all other traffic. Anomaly detection engines must protect the network from new and unknown threats before the vulnerability is discovered and an attack is launched. Thus, the engine should integrate intelligent "learning" capabilities. The principal way for achieving this goal is to model anticipated network traffic behavior, and to use this model for identifying anomalies. The scope of this research focuses primarily on denial of service (DoS) attacks and distributed DoS (DDoS). Our goal is detection and prevention of attacks. The main challenges include minimizing the false-positive rate and the memory consumption. In this paper, we present the MULAN-filter. The MULAN (MUlti-Level Adaptive Network) filter is an accurate engine that uses multi-level adaptive structure for specifically detecting suspicious traffic using a relatively small memory size.© Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering 2010.

Cite

CITATION STYLE

APA

Tzur-David, S., Dolev, D., & Anker, T. (2009). MULAN: Multi-Level Adaptive Network filter. In Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering (Vol. 19 LNICST, pp. 71–90). https://doi.org/10.1007/978-3-642-05284-2_5

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free