RUS  ENG
Full version
JOURNALS // Informatics and Automation // Archive

Tr. SPIIRAN, 2013 Issue 27, Pages 172–180 (Mi trspy609)

Approach to creating normal functioning profile of monitored objects for network anomalies detection

A. V. Guirik, G. P. Shigulin

National Research University of Information Technologies, Mechanics and Optics

Abstract: An approach to creating normal functioning profiles (NFP) of monitored objects is considered. NFP creation is one of the key steps in solving problems of network anomalies detection. Common issues of NFP creation and ways of overcoming these issues are considered. Iteration methods, Shiskin–Eisenpress method in particular, are proposed as a mathematical tool for NFP creation procedure. Described NFP creation method is verified on empirical network monitoring data and suggested suitable for network anomalies detection.

Keywords: network anomalies, intrusion detection, normal functioning profile, information security.

UDC: 004.056, 519.812.3

Received: 26.03.2013



© Steklov Math. Inst. of RAS, 2024