Network Anomaly Detection: Flow-based or Packet-based Approach?

Computer Science – Networking and Internet Architecture

Scientific paper

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

Published on Chonnam National University Networking Journal, Gwangju, Korea June 2008

Scientific paper

One of the most critical tasks for network administrator is to ensure system uptime and availability. For the network security, anomaly detection systems, along with firewalls and intrusion prevention systems are the must-have tools. So far in the field of network anomaly detection, people are working on two different approaches. One is flow-based; usually rely on network elements to make so-called flow information available for analysis. The second approach is packet-based; which directly analyzes the data packet information for the detection of anomalies. This paper describes the main differences between the two approaches through an in-depth analysis. We try to answer the question of when and why an approach is better than the other. The answer is critical for network administrators to make their choices in deploying a defending system, securing the network and ensuring business continuity.

No associations

LandOfFree

Say what you really think

Search LandOfFree.com for scientists and scientific papers. Rate them and share your experience with other people.

Rating

Network Anomaly Detection: Flow-based or Packet-based Approach? does not yet have a rating. At this time, there are no reviews or comments for this scientific paper.

If you have personal experience with Network Anomaly Detection: Flow-based or Packet-based Approach?, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Network Anomaly Detection: Flow-based or Packet-based Approach? will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFWR-SCP-O-102086

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.