Computer Intrusion Detection and Network Monitoring: A Statistical Viewpoint
暫譯: 計算機入侵檢測與網路監控:統計觀點

David J. Marchette

  • 出版商: Springer
  • 出版日期: 2001-06-26
  • 售價: $2,524
  • 語言: 英文
  • 頁數: 333
  • 裝訂: Hardcover
  • ISBN: 0387952810
  • ISBN-13: 9780387952819
  • 下單後立即進貨 (約5~7天)

買這商品的人也買了...

商品描述

Description

This book covers the basic statistical and analytical techniques of computer intrusion detection. It is aimed at both statisticians looking to become involved in the data analysis aspects of computer security and computer scientists looking to expand their toolbox of techniques for detecting intruders. The book is self-contained, assumng no expertise in either computer security or statistics. It begins with a description of the basics of TCP/IP, followed by chapters dealing with network traffic analysis, network monitoring for intrusion detection, host based intrusion detection, and computer viruses and other malicious code. Each section develops the necessary tools as needed. There is an extensive discussion of visualization as it relates to network data and intrusion detection. The book also contains a large bibliography covering the statistical, machine learning, and pattern recognition literature related to network monitoring and intrusion detection. David Marchette is a scientist at the Naval Surface Warfacre Center in Dalhgren, Virginia. He has worked at Navy labs for 15 years, doing research in pattern recognition, computational statistics, and image analysis. He has been a fellow by courtesy in the mathematical sciences department of the Johns Hopkins University since 2000. He has been working in conputer intrusion detection for several years, focusing on statistical methods for anomaly detection and visualization. Dr. Marchette received a Masters in Mathematics from the University of California, San Diego in 1982 and a Ph.D. in Computational Sciences and Informatics from George Mason University in 1996.

 

Table of Contents

Part I: Networking Basics: TCP/IP * Network Statistics * Evaluation * Part II: Intrusion Detection: Network Monitoring * Host Monitoring * Part III: Viruses and Other Creatures: Computer Viruses and Worms * Trojan Programs and Covert Channels * Appendices: Well Known Port Numbers * Trojan Port Numbers * Country Codes * Security Web Sites

商品描述(中文翻譯)

描述
本書涵蓋計算機入侵檢測的基本統計和分析技術。它旨在幫助希望參與計算機安全數據分析的統計學家,以及希望擴展其檢測入侵者技術工具箱的計算機科學家。本書是自足的,假設讀者對計算機安全或統計學沒有專業知識。內容從TCP/IP的基本概念開始,接著是有關網絡流量分析、入侵檢測的網絡監控、基於主機的入侵檢測,以及計算機病毒和其他惡意代碼的章節。每個部分根據需要發展必要的工具。書中對於與網絡數據和入侵檢測相關的可視化進行了廣泛的討論。本書還包含大量的參考文獻,涵蓋與網絡監控和入侵檢測相關的統計、機器學習和模式識別文獻。David Marchette是位於維吉尼亞州Dalhgren的海軍水面作戰中心的科學家。他在海軍實驗室工作了15年,從事模式識別、計算統計和圖像分析的研究。自2000年以來,他一直是約翰霍普金斯大學數學科學系的名譽研究員。他在計算機入侵檢測方面工作了幾年,專注於異常檢測和可視化的統計方法。Marchette博士於1982年在加州大學聖地亞哥分校獲得數學碩士學位,並於1996年在喬治梅森大學獲得計算科學和信息學博士學位。

目錄
第一部分:網絡基礎:TCP/IP * 網絡統計 * 評估 * 第二部分:入侵檢測:網絡監控 * 主機監控 * 第三部分:病毒和其他生物:計算機病毒和蠕蟲 * 特洛伊程序和隱蔽通道 * 附錄:知名端口號 * 特洛伊端口號 * 國家代碼 * 安全網站