Repository logo
Article

Application of the Complex Event Processing system for anomaly detection and network monitoring

creativeworkseries.issn1508-2806
dc.contributor.authorFrankowski, Gerard
dc.contributor.authorJerzak, Marcin
dc.contributor.authorMiłostan, Maciej
dc.contributor.authorNowak, Tomasz
dc.contributor.authorPawłowski, Marek
dc.date.available2017-09-21T07:45:08Z
dc.date.issued2015
dc.descriptionBibliogr. s. 369-371.
dc.description.abstractProtection of infrastructures for e-science, including grid environments and NREN facilities, requires the use of novel techniques for anomaly detection and network monitoring. The aim is to raise situational awareness and provide early warning capabilities. The main operational problem that most network operators face is integrating and processing data from multiple sensors and systems placed at critical points of the infrastructure. From a scientific point of view, there is a need for the efficient analysis of large data volumes and automatic reasoning while minimizing detection errors. In this article, we describe two approaches to Complex Event Processing used for network monitoring and anomaly detection and introduce the ongoing SECOR project (Sensor Data Correlation Engine for Attack Detection and Support of Decision Process), supported by examples and test results. The aim is to develop methodology that allows for the construction of next-generation IDS systems with artificial intelligence, capable of performing signature-less intrusion detection.en
dc.description.placeOfPublicationKraków
dc.description.versionwersja wydawniczapl
dc.identifier.doihttps://doi.org/10.7494/csci.2015.16.4.351
dc.identifier.eissn2300-7036
dc.identifier.issn1508-2806
dc.identifier.nukatdd2016318022pl
dc.identifier.urihttps://repo.agh.edu.pl/handle/AGH/49492
dc.language.isoeng
dc.publisherWydawnictwa AGH
dc.relation.ispartofComputer Science
dc.rightsAttribution 4.0 International
dc.rights.accessotwarty dostęp
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/legalcode
dc.subjectnetwork monitoringen
dc.subjectintrusion detectionen
dc.subjectanomaly detectionen
dc.subjectcomplex event processingen
dc.titleApplication of the Complex Event Processing system for anomaly detection and network monitoringen
dc.title.relatedComputer Science
dc.typeartykuł
dspace.entity.typePublication
publicationissue.issueNumberNo. 4
publicationissue.paginationpp. 351-371
publicationvolume.volumeNumberVol. 16
relation.isJournalIssueOfPublication4655bce0-0075-455f-b0ee-b6dfd4bee276
relation.isJournalIssueOfPublication.latestForDiscovery4655bce0-0075-455f-b0ee-b6dfd4bee276
relation.isJournalOfPublication020291ee-249b-4dcf-98a3-276a2f7981aa

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
csci.2015.16.4.351.pdf
Size:
947.56 KB
Format:
Adobe Portable Document Format