Network Traffic Anomaly Detection and Prevention: Concepts, Techniques, and Tools (Computer Communications and Networks)
暫譯: 網路流量異常偵測與防護:概念、技術與工具(計算機通信與網路)

Monowar H. Bhuyan, Dhruba K. Bhattacharyya, Jugal K. Kalita

  • 出版商: Springer
  • 出版日期: 2017-09-19
  • 售價: $3,490
  • 貴賓價: 9.5$3,316
  • 語言: 英文
  • 頁數: 263
  • 裝訂: Hardcover
  • ISBN: 3319651862
  • ISBN-13: 9783319651866
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

This indispensable text/reference presents a comprehensive overview on the detection and prevention of anomalies in computer network traffic, from coverage of the fundamental theoretical concepts to in-depth analysis of systems and methods. Readers will benefit from invaluable practical guidance on how to design an intrusion detection technique and incorporate it into a system, as well as on how to analyze and correlate alerts without prior information.

Topics and features: introduces the essentials of traffic management in high speed networks, detailing types of anomalies, network vulnerabilities, and a taxonomy of network attacks; describes a systematic approach to generating large network intrusion datasets, and reviews existing synthetic, benchmark, and real-life datasets; provides a detailed study of network anomaly detection techniques and systems under six different categories: statistical, classification, knowledge-base, cluster and outlier detection, soft computing, and combination learners; examines alert management and anomaly prevention techniques, including alert preprocessing, alert correlation, and alert post-processing; presents a hands-on approach to developing network traffic monitoring and analysis tools, together with a survey of existing tools; discusses various evaluation criteria and metrics, covering issues of accuracy, performance, completeness, timeliness, reliability, and quality; reviews open issues and challenges in network traffic anomaly detection and prevention.

This informative work is ideal for graduate and advanced undergraduate students interested in network security and privacy, intrusion detection systems, and data mining in security. Researchers and practitioners specializing in network security will also find the book to be a useful reference.

商品描述(中文翻譯)

這本不可或缺的文本/參考書提供了有關計算機網絡流量異常檢測和預防的全面概述,涵蓋了基本理論概念到系統和方法的深入分析。讀者將受益於寶貴的實用指導,了解如何設計入侵檢測技術並將其整合到系統中,以及如何在沒有先前信息的情況下分析和關聯警報。

主題和特點:介紹高速網絡流量管理的基本要素,詳細說明異常類型、網絡漏洞以及網絡攻擊的分類;描述生成大型網絡入侵數據集的系統方法,並回顧現有的合成數據集、基準數據集和實際數據集;提供對六種不同類別的網絡異常檢測技術和系統的詳細研究:統計、分類、知識庫、聚類和異常檢測、軟計算和組合學習者;檢查警報管理和異常預防技術,包括警報預處理、警報關聯和警報後處理;提出開發網絡流量監控和分析工具的實踐方法,並調查現有工具;討論各種評估標準和指標,涵蓋準確性、性能、完整性、及時性、可靠性和質量等問題;回顧網絡流量異常檢測和預防中的開放問題和挑戰。

這本資訊豐富的著作非常適合對網絡安全和隱私、入侵檢測系統以及安全數據挖掘感興趣的研究生和高年級本科生。專注於網絡安全的研究人員和從業者也會發現這本書是一本有用的參考資料。