Welcome bbc781, the newest member
New user?    Register    Login
http://www.attackprevention.com


Date Submitted: 05/14/05
Hits: 53
Rating: 00000 based on 0 votes

Flow Based Observations from NETI@home and Honeynet Data



Added by Papergrl

Description: We conduct a flow based comparison of honeynet traffic, representing malicious traffic, and NETI@home traffic, representing typical end user traffic. We present a cumulative distribution function of the number of packets for a TCP flow and learn that a large portion of these flows in both datasets are failed and potentially malicious connection attempts. Next, we look at a histogram of TCP port activity over large time scales to gain insight into port scanning and worm activity.

Read the Complete Paper



You don't have permission to post replies.

Please login or register.

Copyright 2008 AttackPrevention