Busca avançada
Ano de início
Entree


Early Detection and Classification of Malicious Activities in Network and Cloud Services

Texto completo
Autor(es):
Coelho, Willen Borges ; Comarela, Giovanni ; Villaca, Rodolfo S.
Número total de Autores: 3
Tipo de documento: Artigo Científico
Fonte: 2024 IEEE 13TH INTERNATIONAL CONFERENCE ON CLOUD NETWORKING, CLOUDNET 2024; v. N/A, p. 9-pg., 2024-01-01.
Resumo

Port scanning is an important technique for collecting sensitive information, highlighting the need for enhanced security systems. It is emphasized that port scanning, considered an anomaly, should be identified and suppressed early, especially given the significant number of reported incidents. In response to this challenge, this paper presents RAVEN, an intelligent and automated system capable of analyzing network flows to detect and classify scans quickly. Contributions include implementing and evaluating RAVEN, demonstrating performance improvement with the expansion of features, and making datasets available to the academic community. Additionally, the RAVEN system is capable of detecting and classifying attacks on web services, including those using the Tor network. Web attacks are quickly detected using Bloom filters, yielding high accuracy. (AU)

Processo FAPESP: 20/05182-3 - PORVIR-5G: programabilidade, orquestração e virtualização em redes 5G
Beneficiário:José Marcos Silva Nogueira
Modalidade de apoio: Auxílio à Pesquisa - Temático