What is it about?
This paper discusses strategies for detecting self/non-self traffic given a set of applications' network profiles. In other words, given a traffic profile of an application, it discusses how we can decide if the current traffic of that application is normal or abnormal.
Featured Image
Why is it important?
It introduces a new strategy for intrusion detection. Compromised systems are likely to exhibit abnormal traffic, but it may be complex to detect it when we consider the overall traffic in a network. On the other hand, if we were able to break down the traffic into different sets, each belonging to the application that produced it, we could tell if that application was or not compromised, given its normal traffic profile.
Perspectives
This approach ressembles other ones, but it has more chances to detect abnormal behaviors (thus, 0-day attacks) and, possibly more important, to pinpoint the exact origin of the problem (i.e., the compromised aplication). Nevertheless, we still have the issue of identifying the source aplication responsible for the traffic.
André Zúquete
Universidade de Aveiro
Read the Original
This page is a summary of: Traffic classification for managing Applications’ networking profiles, Security and Communication Networks, July 2016, Wiley,
DOI: 10.1002/sec.1516.
You can read the full text:
Contributors
The following have contributed to this page







