ASAP : automatic semantics-aware analysis of network payloads

dc.bibliographicCitation.seriesTitleWIAS Preprintseng
dc.bibliographicCitation.volume1502
dc.contributor.authorKrueger, Tammo
dc.contributor.authorKrämer, Nicole
dc.contributor.authorRieck, Konrad
dc.date.accessioned2016-03-24T17:38:37Z
dc.date.available2019-06-28T08:05:16Z
dc.date.issued2010
dc.description.abstractAutomatic inspection of network payloads is a prerequisite for effective analysis of network communication. Security research has largely focused on network analysis using protocol specifications, for example for intrusion detection, fuzz testing and forensic analysis. The specification of a protocol alone, however, is often not sufficient for accurate analysis of communication, as it fails to reflect individual semantics of network applications. We propose a framework for semantics-aware analysis of network payloads which automaticylly extracts semantic components from recorded network traffic. Our method proceeds by mapping network payloads to a vector space and identifying semantic templates corresponding to base directions in the vector space. We demonstrate the efficacy of semantics-aware analysis in different security applications: automatic discovery of patterns in honeypot data, analysis of malware communication and network intrusion detection.eng
dc.description.versionpublishedVersioneng
dc.formatapplication/pdf
dc.identifier.issn0946-8633
dc.identifier.urihttps://doi.org/10.34657/2027
dc.identifier.urihttps://oa.tib.eu/renate/handle/123456789/2288
dc.language.isoengeng
dc.publisherBerlin : Weierstraß-Institut für Angewandte Analysis und Stochastikeng
dc.relation.issn0946-8633eng
dc.rights.licenseThis document may be downloaded, read, stored and printed for your own use within the limits of § 53 UrhG but it may not be distributed via the internet or passed on to external parties.eng
dc.rights.licenseDieses Dokument darf im Rahmen von § 53 UrhG zum eigenen Gebrauch kostenfrei heruntergeladen, gelesen, gespeichert und ausgedruckt, aber nicht im Internet bereitgestellt oder an Außenstehende weitergegeben werden.ger
dc.subject.ddc510eng
dc.subject.otherdimensionality reductioneng
dc.subject.othercomputer securityeng
dc.subject.otherintrusion detectioneng
dc.titleASAP : automatic semantics-aware analysis of network payloadseng
dc.typeReporteng
dc.typeTexteng
tib.accessRightsopenAccesseng
wgl.contributorWIASeng
wgl.subjectMathematikeng
wgl.typeReport / Forschungsbericht / Arbeitspapiereng
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
664831966.pdf
Size:
370.45 KB
Format:
Adobe Portable Document Format
Description: