Can I read PHAD: Detecting Network Traffic Anomalies on EtoBox?
PHAD: Detecting Network Traffic Anomalies by Hiếu Andree is a document available to read on EtoBox.
What is PHAD: Detecting Network Traffic Anomalies about?
PHAD is an experimental packet header anomaly detector that learns normal values for 33 fields in network protocol headers. It detects anomalies by comparing values to a probability distribution estimated from a training period of attack-free traffic. On a 1999 DARPA dataset, PHAD detected 72 of 201 attacks with only 10 false alarms per day, focusing more on anomalous protocol fields than addresses/ports. The paper describes the design of PHAD and evaluates its performance at detecting a variety of attack t
- Author
- Hiếu Andree
- Language
- EN